SCS-C02 Data Protection Practice Question
A company is using AWS DMS to migrate data from an on-premises Oracle database to Amazon RDS for PostgreSQL. The data must be encrypted in transit. What should the company do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable SSL on the source and target endpoints in the DMS task.
AWS DMS supports SSL/TLS to encrypt data in transit between source and target endpoints. Enabling SSL on both endpoints ensures that the data migration is encrypted over the network. Option A is incorrect because AWS Direct Connect provides a private network connection but does not automatically encrypt traffic; additional encryption like SSL is still required for data in transit. Option C is incorrect because AWS KMS is used for encryption at rest, not for encrypting data in transit. Option D is incorrect because a VPN connection provides a secure tunnel but is not necessary; DMS can use SSL directly on the endpoints, which is a simpler solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Direct Connect to establish a private connection.
Why it's wrong here
AWS Direct Connect establishes a dedicated, private network connection between your on-premises environment and AWS, bypassing the public internet. However, this private transport itself does not automatically encrypt data; it only provides a low-latency, consistent network path. Without an additional encryption layer such as SSL/TLS or IPsec, data leaving your on-premises databases remains in clear text over the Direct Connect link. So while Direct Connect can improve network reliability for DMS, it does not satisfy the requirement to encrypt data in transit.
- ✓
Enable SSL on the source and target endpoints in the DMS task.
Why this is correct
AWS DMS has native support for SSL/TLS encryption between the replication instance and both the source and target endpoints. For each endpoint, you can specify an SSL mode (e.g., require for Oracle, SQL Server, and PostgreSQL, or verify-ca for Aurora MySQL) so that all data transferred between the database and DMS is encrypted in transit. With SSL enabled, DMS negotiates an encrypted connection directly with the database engines, ensuring data is protected without relying on additional VPN or network manipulation. This is the most direct and appropriate way to encrypt migration traffic in AWS DMS.
- ✗
Use AWS KMS to encrypt the data before sending.
Why it's wrong here
AWS KMS (Key Management Service) is designed to manage encryption keys for data at rest, not data in transit. KMS lets you create and control customer master keys used to encrypt EBS volumes, S3 objects, RDS storage, and other resources, but it does not intercept or encrypt network traffic moving through DMS. If you wanted to encrypt data before sending it, you would need to use client-side encryption at the application layer—KMS alone cannot protect data while it flows from the source database to the DMS replication instance. Therefore, KMS is simply the wrong tool for encrypting in-flight DMS data.
- ✗
Set up a VPN connection between the on-premises network and AWS VPC.
Why it's wrong here
While an AWS Site-to-Site VPN creates an encrypted IPsec tunnel from your on-premises network to the AWS VPC, that tunnel only encrypts the network path between your environment and AWS. DMS, however, supports SSL/TLS encryption directly on its source and target endpoint connections, which provides end-to-end encryption of the database communication itself. Adding a VPN would mean traffic from the source database to the DMS replication instance is encrypted across the tunnel, but DMS’s built-in SSL feature is a more straightforward, easier-to-manage solution and does not require network-level changes. Additionally, VPN setup introduces latency and administrative overhead that is unnecessary for this requirement.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.