SCS-C02 Data Protection Practice Question
A company needs to encrypt data at rest in Amazon Redshift. They want to use an AWS KMS customer managed key. What is the correct procedure to enable encryption for an existing Redshift cluster?
⚠ Common exam trap
It's easy for candidates to assume encryption can be toggled on an existing cluster via console or CLI commands, similar to services like RDS or EBS, but Redshift enforces encryption as a cluster-level immutable property.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Take a snapshot of the cluster, restore it to a new cluster with encryption enabled, and point applications to the new cluster.
Amazon Redshift does not support enabling encryption on an existing cluster directly. The only way to transition an unencrypted cluster to an encrypted one is to take a snapshot of the cluster, restore it to a new cluster with encryption enabled using a KMS customer managed key, and then redirect applications to the new cluster. This is because encryption settings are immutable after cluster creation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable encryption using the Redshift console by selecting the KMS key.
Why it's wrong here
The Redshift console exposes encryption settings only during cluster creation. When you select an existing cluster in the console, the Configuration tab does not include any option to enable encryption or attach a KMS key, nor does it allow editing the cluster's encryption property. Attempting to locate such a control reveals no supported UI path, so this action cannot be performed for an already-running cluster.
- ✗
Use the AWS CLI command 'aws redshift modify-cluster' with --encrypted flag.
Why it's wrong here
The `aws redshift modify-cluster` CLI command does not have a parameter named `--encrypted`. The ModifyCluster API only accepts parameters such as `--node-type`, `--number-of-nodes`, and `--cluster-parameter-group`; encryption-related flags exist only on `create-cluster`. Therefore, running this command with `--encrypted` would produce an 'Unknown options' error, not a rejection based on cluster state.
- ✗
Modify the cluster and enable encryption with the KMS key.
Why it's wrong here
Amazon Redshift treats encryption as an immutable, cluster-defining attribute; it cannot be toggled after provisioning. The ModifyCluster operation will reject any request that attempts to change the cluster's encryption status, and the AWS Management Console likewise has no 'Modify' workflow for encryption. This is not a matter of missing KMS configuration—the service simply does not support in-place encryption changes, requiring a snapshot/restore instead.
- ✓
Take a snapshot of the cluster, restore it to a new cluster with encryption enabled, and point applications to the new cluster.
Why this is correct
To add encryption to an existing Redshift cluster, take a snapshot of the source cluster and restore it as a new cluster while specifying a KMS key in the restore settings. The restore operation initializes a fresh cluster with encryption enabled at the storage layer, then you can update your application's JDBC/ODBC connection strings and DNS to point to the new endpoint. Once verified, you can retire the old cluster. This is the only AWS-supported path for retrofitting encryption.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.