Courseiva
Data Protection →easyMultiple Choice

SCS-C02 Data Protection Practice Question

A company is migrating sensitive customer data to Amazon RDS for MySQL. The security team requires that data be encrypted at rest and in transit. The database will be accessed by a web application running on Amazon EC2 instances in the same VPC. The RDS instance is launched with encryption enabled using an AWS managed KMS key. The security team also enables SSL/TLS for connections. Which additional step is necessary to ensure that the web application uses encrypted connections?

⚠ Common exam trap

The trap is thinking that enabling SSL/TLS on RDS is sufficient; candidates may overlook that the client application must be configured to use SSL/TLS, and they may confuse encryption at rest (KMS) with encryption in transit (SSL/TLS).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the web application's database connection string to use SSL/TLS.

Enabling SSL/TLS on the RDS instance allows encrypted connections, but the web application must be configured to actually use SSL/TLS when connecting. This is done by modifying the database connection string to require SSL/TLS. Without this step, the application may connect without encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable encryption at rest on the EC2 instance's EBS volumes.

    Why it's wrong here

    Enabling EBS encryption on the EC2 instance only protects the local block storage volumes attached to that instance. The database connection flows over the network between the EC2 instance and the RDS endpoint, and EBS encryption does nothing to encrypt this network traffic. Because the sensitive data in transit remains plaintext, this measure is not an effective way to protect database connections.

  • ✗

    Create an SCP to enforce SSL connections to RDS.

    Why it's wrong here

    Service control policies are AWS Organizations-level guardrails that restrict the IAM actions an account or principal can perform; they cannot inspect or alter database protocol behavior. RDS does support SSL/TLS, but the decision to use an encrypted connection is made by the client library based on its connection configuration. An SCP cannot enforce that an application's JDBC or ODBC connection string specifies TLS, so it would have no effect on the actual connection security.

  • ✓

    Configure the web application's database connection string to use SSL/TLS.

    Why this is correct

    The web application must explicitly request TLS because RDS defaults to allowing both encrypted and unencrypted connections depending on the client. Adding an SSL/TLS option to the connection string—such as 'sslMode=require' or 'sslmode=verify-full'—forces the client to negotiate an encrypted channel. This is the only option that directly controls the confidentiality of data as it travels from the application to the RDS database.

  • ✗

    Grant the EC2 instance's IAM role permission to use the KMS key for decrypting RDS connections.

    Why it's wrong here

    KMS keys, including ones granted to an EC2 instance's IAM role, are used to encrypt/decrypt data at rest such as RDS storage volumes or EBS snapshots, not to protect network connections. TLS/SSL session keys are generated by the client and server during the handshake using certificates and key exchange algorithms, not by KMS. Furthermore, granting IAM role permissions to use a KMS key would affect API calls to AWS services, not the database user authentication or wire-level encryption.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.