SCS-C02 Infrastructure Security Practice Question
A company wants to ensure that all data in transit between its EC2 instances and an RDS database is encrypted. The instances and the database are in the same VPC. Which configuration step is necessary to achieve this?
⚠ Common exam trap
Watch out — candidates often confuse encryption at rest (Option A) with encryption in transit, or assume that security groups (Option C) can enforce encryption, when in fact they only filter traffic at the network layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable SSL/TLS on the RDS instance and configure the EC2 instances to connect using SSL.
To encrypt data in transit between EC2 instances and an RDS database within the same VPC, you must enable SSL/TLS on the RDS instance and configure the EC2 instances to connect using SSL. This ensures that the network traffic is encrypted at the transport layer, protecting against eavesdropping or man-in-the-middle attacks. AWS RDS supports SSL/TLS for most database engines, and the client must explicitly request an encrypted connection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable encryption at rest for the RDS instance using AWS KMS.
Why it's wrong here
Encryption at rest via AWS KMS protects the RDS data files, snapshots, and automated backups on disk, but it does nothing for traffic on the wire. Data in transit between your EC2 instance and the database travels over the network as plaintext unless an encryption protocol such as TLS/SSL is explicitly used. KMS-managed keys for RDS encryption are unrelated to securing client-to-database connections.
- ✗
Set up a VPN connection between the EC2 instances and the RDS database.
Why it's wrong here
An AWS Site-to-Site VPN is designed to connect an on-premises network to a VPC, not to encrypt traffic between two resources that already reside in the same VPC. EC2 instances and an RDS database communicate directly over the VPC's private network; introducing a VPN tunnel between them is incorrect and would not be supported as a standard RDS connection path. The proper way to encrypt this in-VPC traffic is to enable SSL/TLS on the database and in the client connection.
- ✗
Configure the security group for the RDS instance to enforce encryption.
Why it's wrong here
A security group acts as a stateful firewall that filters allowed traffic based on source IP, port, and protocol; it has no awareness of application-layer payloads and cannot force a database engine to encrypt its traffic. Even if the security group restricts access to the RDS port, connections that are permitted may still be transmitted in plaintext. Encryption enforcement must happen at the database layer, for example by requiring SSL/TLS via RDS parameter settings or connection string options.
- ✓
Enable SSL/TLS on the RDS instance and configure the EC2 instances to connect using SSL.
Why this is correct
Enabling SSL/TLS on the RDS instance makes the database server accept and require encrypted connections, and configuring the EC2 clients to connect with SSL (for example, using sslmode=require or verify-full in PostgreSQL, or useSSL=true in MySQL) encrypts all data in flight between the application and the database. RDS provides server certificates for each region that clients can validate to prevent man-in-the-middle attacks. This directly satisfies the requirement that all data in transit be encrypted.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.