Courseiva
Data Protection →hardMultiple Choice

SCS-C02 Data Protection Practice Question

A financial services company must ensure that all data at rest in Amazon RDS for PostgreSQL is encrypted. The current database is unencrypted. What is the MOST operationally efficient way to enable encryption?

⚠ Common exam trap

SCS-C02 often tests the method to encrypt an existing unencrypted RDS instance, and candidates may incorrectly believe that encryption can be enabled by modifying the instance or by creating a read replica.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Take a snapshot of the database, copy the snapshot with encryption enabled, and restore the encrypted snapshot to a new DB instance.

The most operationally efficient way to enable encryption on an existing unencrypted RDS for PostgreSQL database is to take a snapshot, copy the snapshot with encryption enabled, and restore it to a new encrypted DB instance. This method leverages RDS's native snapshot and restore capabilities, minimizing manual intervention and downtime. Other methods like exporting and importing data are more complex and time-consuming, and encryption cannot be enabled directly on an existing instance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Export the database to S3 using pg_dump, then import into a new encrypted RDS instance.

    Why it's wrong here

    Although pg_dump can export the data and a newly created RDS instance can be encrypted at launch, this approach is manual and operationally heavy. You must manage downtime or write quiescence during the dump and import, and you lose the convenience of restoring an existing snapshot with the same instance settings, automated backup timeline, and native RDS metadata. AWS's snapshot-copy-restore path is simpler, less error-prone, and preserves the database engine configuration without requiring custom import tooling.

  • ✗

    Create a read replica with encryption enabled and promote it to primary.

    Why it's wrong here

    A read replica's encryption status is inherited from its source DB instance, so you cannot create an encrypted read replica from an unencrypted source. If the source is unencrypted, the replica is also unencrypted, and the AWS API/Console does not allow you to specify a KMS key for that replica. Therefore, promoting such a replica would still leave the data unencrypted at rest and does not satisfy the requirement.

  • ✓

    Take a snapshot of the database, copy the snapshot with encryption enabled, and restore the encrypted snapshot to a new DB instance.

    Why this is correct

    This is the officially supported AWS method for adding encryption at rest to an existing unencrypted RDS instance. You take a manual snapshot, copy that snapshot while specifying a KMS key (which encrypts the snapshot copy), and then restore the encrypted snapshot to a new DB instance. The restored instance is encrypted at the storage layer, and you can repoint your application to its new endpoint before decommissioning the original instance. After creation, encryption on that restored instance cannot be disabled.

  • ✗

    Enable encryption directly on the existing RDS instance by modifying the DB instance settings.

    Why it's wrong here

    Modifying an unencrypted Amazon RDS instance's settings to enable encryption is not possible. Encryption status is a fundamental configuration set during instance creation and cannot be altered afterwards for an unencrypted instance. This option is tempting because modifying DB instance settings is the standard procedure for changing many other parameters, such as instance class or storage. It would also be the correct method to enable encryption when creating a *new* instance, or to rotate the encryption key on an *already encrypted* instance.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.