Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company wants to ensure that all traffic to and from an Amazon RDS instance is encrypted in transit. Which solution should the security engineer implement?

⚠ Common exam trap

Many candidates confuse encryption at rest (KMS) with encryption in transit (SSL/TLS), leading them to select Option A, which does not address network traffic encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the database to require SSL/TLS connections and modify clients to connect using SSL.

Encrypting data in transit for Amazon RDS requires enabling SSL/TLS on the database instance and configuring client connections to use SSL/TLS. This ensures that all traffic between the client and the RDS instance is encrypted using TLS protocols, protecting against eavesdropping and man-in-the-middle attacks. Amazon RDS supports SSL/TLS for all database engines, and you can enforce SSL connections by setting the 'require_secure_transport' parameter (MySQL) or similar parameters for other engines.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable encryption at rest using AWS KMS.

    Why it's wrong here

    Enabling encryption at rest with AWS KMS protects the RDS storage volumes, automated backups, and snapshots by encrypting the data as it is written to disk. However, this mechanism does absolutely nothing to protect the data while it is in motion between the EC2 instance and the RDS database over the network. The requirement is specifically about traffic, so KMS encryption at rest is outside the scope of the objective.

  • ✓

    Configure the database to require SSL/TLS connections and modify clients to connect using SSL.

    Why this is correct

    RDS natively supports SSL/TLS for encrypting the connection between a client and your database. You must set the database parameter group to require a secure connection (for example, 'require_secure_transport=ON' for MySQL, or use the rds-force-ssl-parameter for PostgreSQL) and then modify your application's connection string to use SSL mode, pointing to the RDS CA certificate. This ensures that all SQL queries, result sets, and authentication data are encrypted in transit, directly satisfying the requirement.

  • ✗

    Use an S3 bucket policy to enforce encryption in transit for all S3 traffic.

    Why it's wrong here

    Using an S3 bucket policy to enforce encryption in transit is a valid approach for S3, because you can apply a condition like 'aws:SecureTransport' to deny HTTP requests. However, the question is about a database service (RDS), not an S3 bucket, so this policy would have no effect on the traffic between your application and the RDS instance. S3 and RDS are separate services, and the policy applies only to S3 API requests, not to database connections.

  • ✗

    Use an AWS Transit Gateway to route traffic through a central VPC.

    Why it's wrong here

    An AWS Transit Gateway is a network transit hub that you use to interconnect VPCs and on-premises networks, simplifying routing and reducing the number of peering connections. While it provides centralized connectivity, it operates at Layer 3 and does not inspect or encrypt individual application connections. Traffic traversing a Transit Gateway remains in the original application protocol and is not encrypted unless the application itself uses TLS, so this option does not address the encryption-in-transit requirement.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.