Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The application uses an Amazon RDS for MySQL database. The security team requires that all data in transit between the EC2 instances and the database be encrypted. The database is in a private subnet. The EC2 instances are in a public subnet. The security team also wants to minimize latency. What should be done to meet these requirements?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable SSL/TLS on the RDS instance and configure the application to use encrypted connections

In a typical AWS environment, data in transit between an application and an RDS database can be encrypted using SSL/TLS. RDS for MySQL supports SSL/TLS connections. To meet the requirement, enable SSL/TLS on the RDS instance by downloading the certificate bundle and configuring the DB instance to require encrypted connections. Then, configure the application to use SSL/TLS when connecting to the database. This approach encrypts data in transit with minimal overhead compared to a VPN, which can introduce latency. Option A (using AWS Certificate Manager for the RDS endpoint) is incorrect because ACM is typically used for load balancers and CloudFront, not for direct database connections. While ACM can provide certificates for applications, RDS itself uses its own certificate authority for SSL/TLS. Option B (setting up an IPsec VPN) is unnecessary and adds complexity and latency without providing encryption specific to the database connection; SSL/TLS already meets the requirement. Option C (placing instances in the same subnet and using a NAT gateway) does not encrypt data in transit and increases latency via NAT gateway.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Certificate Manager to issue a certificate for the RDS endpoint

    Why it's wrong here

    AWS Certificate Manager (ACM) issues public and private certificates for use exclusively with integrated AWS services such as Application Load Balancers, CloudFront, and API Gateway, not for database engines. RDS instances do not accept ACM certificates because the certificate store is managed by the database engine itself; an RDS instance maintains its own CA-signed server certificate for SSL/TLS connections. Attempting to use an ACM certificate for the RDS endpoint would be invalid because the client would not be able to validate the chain against the RDS root CA, and ACM does not provide a mechanism to install certificates onto RDS.

  • ✗

    Set up a VPN connection between the EC2 instances and the RDS instance using an IPsec VPN

    Why it's wrong here

    RDS is a fully managed service that does not support terminating IPsec VPN tunnels directly on the database endpoint; VPN connections are designed to facilitate secure connectivity between on-premises networks and the VPC, not to encrypt application-to-database traffic within the same VPC. Even if a VPN were established, traffic from EC2 to the RDS endpoint would still traverse the VPC network unencrypted unless the database client explicitly uses TLS. Implementing an IPsec VPN would also add considerable complexity and latency for no benefit when RDS already supports native SSL/TLS encryption for data in transit.

  • ✗

    Place the EC2 instances and RDS in the same subnet and use a NAT gateway

    Why it's wrong here

    Placing EC2 instances and an RDS database in the same subnet only ensures low-latency network paths; it does nothing to encrypt communications, and AWS does not provide automatic confidentiality for traffic within a VPC. A NAT gateway is an outbound internet translation device that allows private instances to reach destinations outside the VPC, and it does not inspect or encrypt payloads between an EC2 instance and a database endpoint. This option therefore leaves the data fully readable on the wire inside the VPC, providing no protection for the sensitive traffic.

  • ✓

    Enable SSL/TLS on the RDS instance and configure the application to use encrypted connections

    Why this is correct

    Enabling SSL/TLS on the RDS instance forces the database server to accept only encrypted connections, typically by setting the force_ssl parameter (for PostgreSQL) or the SSL/TLS requirement (for MySQL) in the DB parameter group. The application must then connect using TLS with the RDS-generated CA certificate in its trust store, and it should enforce certificate verification to prevent man-in-the-middle attacks. This encrypts all data in transit between the EC2 instances and the RDS endpoint, satisfying the confidentiality requirement with minimal latency overhead and without needing extra networking equipment.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.