Courseiva
Data Protection →easyMultiple Choice

SCS-C02 Data Protection Practice Question

A company needs to encrypt data in transit between an EC2 instance and an RDS database. Which option should be used?

⚠ Common exam trap

Watch out — candidates often confuse encryption at rest (EBS or RDS encryption) with encryption in transit, or mistakenly think that KMS keys can be directly applied to network connections, when in fact SSL/TLS is the correct mechanism for securing data in motion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the database to use SSL/TLS connections

Encrypting data in transit between an EC2 instance and an RDS database requires the use of SSL/TLS protocols to secure the communication channel. AWS RDS supports SSL/TLS connections by enabling the `require_secure_transport` parameter or using a certificate bundle on the client side, ensuring that all data transmitted over the network is encrypted and protected from eavesdropping or man-in-the-middle attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable encryption at rest for the RDS instance

    Why it's wrong here

    Enabling encryption at rest for an RDS instance uses AES-256 to encrypt the underlying storage volumes, automated backups, snapshots, and read replicas. That protection is entirely transparent to network traffic, so the SQL queries and credentials moving between your EC2 instance and the database endpoint can still be captured and read from the wire. This setting is required for compliance at rest, but it does nothing for data in transit.

  • ✓

    Configure the database to use SSL/TLS connections

    Why this is correct

    To encrypt data in transit, you must configure the database client and server to negotiate a TLS session. On RDS, this means importing the Amazon RDS CA certificate into the client's trust store and setting the database parameter group's `rds.force_ssl` (PostgreSQL) or `require_secure_transport` (MySQL/MariaDB) parameter to 1. Once enabled, TLS encrypts the entire database protocol stream, including authentication, query text, and result sets, and the client can verify that it is connecting to the genuine RDS endpoint, not an impostor.

  • ✗

    Use an AWS KMS key to encrypt the connection

    Why it's wrong here

    AWS KMS is a managed service that creates, rotates, and controls envelope encryption keys; it does not sit in the network path between EC2 and RDS. A KMS key can be used to encrypt data at rest, or to generate data keys for client-side encryption, but it cannot establish an encrypted session on the database connection itself. Encrypting the connection requires a protocol-level mechanism such as TLS, which performs its own handshake and exchanges session keys, independent of any KMS API call.

  • ✗

    Enable EBS encryption on the EC2 instance

    Why it's wrong here

    EBS encryption protects the EC2 instance's attached block device at rest by encrypting data as it is written to the underlying volume, and transparently decrypting it when read by the kernel. That is a storage-layer feature that has no effect on the network interfaces or TCP sockets used to reach the RDS database. The traffic between the EC2 instance's ENI and the RDS endpoint remains plaintext unless an application-level encryption protocol such as TLS is applied, so EBS encryption cannot prevent sniffing or eavesdropping in transit.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.