SCS-C02 Data Protection Practice Question
A company uses Amazon RDS for MySQL with encryption at rest enabled using AWS KMS. They need to ensure that automated backups and snapshots are also encrypted. Which configuration is required?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No additional configuration is needed; backups are encrypted automatically.
Amazon RDS automatically encrypts automated backups and snapshots when the source database is encrypted at rest. This encryption is inherited from the primary database, so no additional steps are required. Options B, C, and D are incorrect: manually encrypting each snapshot is unnecessary; assigning a new KMS key to backups is not required; and enabling encryption after creation is not possible for an existing unencrypted instance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
No additional configuration is needed; backups are encrypted automatically.
Why this is correct
Because the RDS MySQL instance already has encryption at rest enabled with a KMS key, all automated backups and manual DB snapshots are encrypted automatically using that same KMS key. AWS handles this at the storage layer with no further input from you, so backup encryption is inherently included.
- ✗
Manually encrypt each snapshot with a separate KMS key.
Why it's wrong here
Manually encrypting each snapshot with a separate KMS key is both unnecessary and not a native backup feature: snapshots inherit the encryption configuration of the source database, so the original CMK already secures them. While you could create a snapshot copy with a different KMS key, doing so is optional and would not replace the automatic encryption already in place.
- ✗
Create a new KMS key and assign it to the backup configuration.
Why it's wrong here
RDS does not expose any backup-level KMS key assignment; the same customer master key that encrypts the database instance is the key used for its automatic backups and snapshots. Creating a new KMS key and attaching it to a 'backup configuration' is not a supported action, and it would add no benefit because the existing key already encrypts all backup data.
- ✗
Enable encryption on the RDS instance after creation.
Why it's wrong here
Encryption at rest on an RDS MySQL instance cannot be enabled after the instance is provisioned; AWS only applies this setting during creation or when you restore a snapshot into a new encrypted instance. Therefore, in this scenario, the instance is already encrypted, and attempting to enable encryption later would be invalid and unnecessary.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.