Courseiva
Data Protection →mediumMultiple Select

SCS-C02 Data Protection Practice Question

A company needs to enforce encryption in transit for all traffic between an Amazon EC2 instance and an Amazon RDS database. Which TWO steps should be taken?

⚠ Common exam trap

SCS-C02 often tests the distinction between encryption at rest (KMS, option D) and encryption in transit (TLS, options A/E); candidates who see 'encrypt' and grab the KMS/at-rest answer miss that the question specifies traffic between EC2 and RDS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable TLS on the RDS database and configure the database to require encrypted connections.

Option A is correct because enforcing encryption in transit for RDS requires enabling TLS on the DB instance and setting the parameter group so the database requires SSL/TLS connections (for example, MySQL's require_secure_transport or PostgreSQL's rds.force_ssl), which rejects unencrypted client sessions. Option E is correct because the client side must actually negotiate TLS: the application on the EC2 instance has to connect using SSL/TLS, typically by supplying the RDS CA certificate (rds-ca-rsa2048-g1 or similar) and using the appropriate driver parameters such as sslmode=require for PostgreSQL or ssl-mode=REQUIRED for MySQL. Option B is not correct because security groups only control network reachability on ports 3306/5432 and do not provide or enforce encryption. Option C is not correct because a VPN encrypts traffic at the network layer between networks but is not the mechanism used to enforce TLS between an EC2 instance and an RDS endpoint, and RDS TLS is the supported approach. Option D is not correct because encryption at rest protects stored data via KMS and does not address data in transit between the EC2 instance and the database.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable TLS on the RDS database and configure the database to require encrypted connections.

    Why this is correct

    Setting `require_secure_transport=1` on MySQL or `rds.force_ssl=1` on PostgreSQL in the RDS parameter group makes the server reject any non-TLS connection, explicitly enforcing encryption at the database layer. This server-side configuration is authoritative: only TLS-enabled clients with the appropriate CA certificate can connect, so plaintext traffic is refused regardless of client-side settings.

  • ✗

    Configure security groups to allow traffic only on port 3306 (MySQL) or 5432 (PostgreSQL).

    Why it's wrong here

    Security group rules that permit traffic only on MySQL's 3306 or PostgreSQL's 5432 restrict which ports and source IPs can reach the database, but those ports carry plaintext or TLS interchangeably. The database protocol does not require encryption merely because a port is open; without enforcing SSL/TLS parameters, an application can still send unencrypted SQL. This rule only controls network access, not the confidentiality of the traffic on the permitted ports.

  • ✗

    Set up a VPN connection between the EC2 instance and the RDS database.

    Why it's wrong here

    A VPN between EC2 and RDS (such as a VPC-to-VPC IPsec tunnel) encrypts the underlying IP packets at the network layer, but the database session itself remains a normal plaintext SQL connection. From the RDS instance's perspective, the connection is not necessarily TLS because the VPN is transparent to the database protocol. Thus, a VPN provides network-layer encryption but does not enforce database-level TLS and does not prevent a client from sending plaintext SQL over the tunnel.

  • ✗

    Enable encryption at rest on the RDS instance.

    Why it's wrong here

    Enabling RDS encryption at rest (via AWS KMS-managed keys for EBS volumes, automated backups, and snapshots) protects stored data on disk, not data in transit between EC2 and RDS. Encryption at rest and encryption in transit are independently configured controls; one does not imply or enable the other. This action has no effect on whether the database traffic traversing the network is encrypted, so it fails the stated requirement.

  • ✓

    Configure the application to connect using TLS/SSL.

    Why this is correct

    Configuring the application to connect using TLS/SSL (for example, `ssl-mode=REQUIRED` in MySQL, `sslmode=require` in PostgreSQL, or `useSSL=true` in JDBC) forces the client to establish an encrypted connection and verify the server certificate against the RDS CA. This addresses the client side of encryption in transit, ensuring that queries and result sets are not sent in plaintext. Note that this must be paired with server-side enforcement (like `require_secure_transport` or `rds.force_ssl`) to prevent other, misconfigured clients from bypassing TLS.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.