SCS-C02 Data Protection Practice Question
A security engineer is tasked with ensuring that all data stored in an RDS DB instance is encrypted at rest. The database is already running and contains data. What should the engineer do?
⚠ Common exam trap
SCS-C02 often tests the immutability of RDS encryption — candidates who assume encryption can be toggled on an existing instance pick the wrong 'modify' option.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a snapshot of the DB instance, copy it with encryption, and restore the encrypted snapshot
RDS encryption at rest can only be enabled at DB instance creation time; it cannot be turned on for an existing unencrypted instance. The supported migration path is to take a snapshot of the unencrypted instance, copy that snapshot with the encryption option enabled (specifying a KMS key), and then restore a new DB instance from the encrypted snapshot. This produces an encrypted instance containing the same data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the KMS key associated with the DB instance
Why it's wrong here
An unencrypted RDS instance has no KMS key associated with it, so there is nothing to 'change' — KMS keys are only attached when encryption is enabled at creation or via snapshot restore. Additionally, RDS does not support in-place modification of the KMS key for an existing instance; even for encrypted instances, you must restore from a snapshot to use a different key. Therefore, this action would not enable encryption at rest on the existing instance.
- ✗
Modify the DB instance to use an encrypted storage type
Why it's wrong here
RDS storage types (e.g., General Purpose SSD, Provisioned IOPS) are not themselves encrypted or unencrypted — encryption-at-rest is a property of the DB instance and its underlying volume, selected at launch. The 'Modify DB instance' operation can adjust storage size, type, or IOPS, but it cannot toggle encryption on an existing instance. Even converting to an encrypted volume type would not encrypt existing data; only a snapshot copy with encryption and restore can do that.
- ✓
Create a snapshot of the DB instance, copy it with encryption, and restore the encrypted snapshot
Why this is correct
To enable encryption-at-rest on an existing unencrypted Amazon RDS DB instance, you must create a manual snapshot, make an encrypted copy of that snapshot (either with the default AWS-managed key or a customer-managed KMS key), and then restore a new DB instance from the encrypted snapshot. During the snapshot copy you can also specify a KMS key; the restored instance will be encrypted, and you can then update your applications' connection strings to point to the new endpoint. This is the documented and only supported approach, since encryption cannot be added in place.
- ✗
Enable encryption at rest in the RDS console for the existing DB instance
Why it's wrong here
The RDS console does not offer a setting to turn on 'encryption at rest' for an already-provisioned instance; the encryption toggle is only presented at instance creation time (or when restoring from a snapshot). Attempting to modify the instance in the console reveals no such field, because AWS does not support in-place encryption enablement. If you need encrypted storage, you must follow the snapshot-copy-restore workflow rather than expecting a console checkbox to flip the encryption state.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.