SCS-C02 Encryption at rest (RDS) Practice Question
A security engineer is designing a solution to protect sensitive data in an Amazon RDS for MySQL database. The data must be encrypted at rest using a key stored in AWS KMS. Additionally, the database must support automated backups and cross-region disaster recovery. Which architecture meets these requirements?
⚠ Common exam trap
SCS-C02 often tests the misconception that encryption can be enabled on an existing RDS instance — candidates forget that encryption must be set at creation and can only be applied to a new instance via snapshot restore.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Launch an encrypted RDS instance using a customer-managed KMS key. Enable automated backups and create a cross-region read replica.
Launching an encrypted RDS instance with a customer-managed KMS key satisfies the encryption-at-rest requirement with control over key rotation and access. Enabling automated backups ensures point-in-time recovery, and creating a cross-region read replica provides cross-region disaster recovery — all requirements are met in a single architecture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Launch an unencrypted RDS instance, then use AWS DMS to replicate data to an encrypted instance in another region.
Why it's wrong here
AWS DMS is a data migration service that copies data on a scheduled or continuous basis, but it does not manage database snapshots, point-in-time recovery, or automatic failover. An unencrypted source instance remains unencrypted at rest, and DMS replication does not create a standby database for disaster recovery. This approach lacks the automated backup and cross-region failover capabilities required by the security engineer.
- ✗
Launch an unencrypted RDS instance, then enable encryption using the AWS Console after creation.
Why it's wrong here
Amazon RDS does not allow enabling encryption on an existing database instance via the console, CLI, or API; encryption must be set at launch time. The unencrypted instance would need to be migrated to a newly launched encrypted instance, often via snapshot restore or DMS, which is not what this option proposes. Therefore, using the console after creation is impossible and the protection requirement is unmet.
- ✗
Launch an encrypted RDS instance using the default KMS key, then export the database to S3 and copy to another region.
Why it's wrong here
Exporting an RDS database or snapshot to Amazon S3 produces a static file copy, not a managed database with automated backup and restore capabilities. Copying that export to another region merely stores data in another location; it does not create a running, recoverable database or provide point-in-time recovery. Additionally, using the default AWS-managed KMS key fails to provide the customer-controlled key management that a security-focused design typically requires.
- ✓
Launch an encrypted RDS instance using a customer-managed KMS key. Enable automated backups and create a cross-region read replica.
Why this is correct
Launching an encrypted RDS instance with a customer-managed KMS key ensures data at rest is protected by an encryption key you create and control. Enabling automated backups provides point-in-time recovery, while a cross-region read replica serves as a disaster recovery target that can be promoted to a primary database in a regional outage. This combination fully meets the requirements for encryption, availability, and automated recovery.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.