Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

A security engineer is tasked with ensuring that all data stored in an RDS DB instance is encrypted at rest. The database is already running and contains data. What should the engineer do?

⚠ Common exam trap

SCS-C02 often tests the immutability of RDS encryption — candidates who assume encryption can be toggled on an existing instance pick the wrong 'modify' option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a snapshot of the DB instance, copy it with encryption, and restore the encrypted snapshot

RDS encryption at rest can only be enabled at DB instance creation time; it cannot be turned on for an existing unencrypted instance. The supported migration path is to take a snapshot of the unencrypted instance, copy that snapshot with the encryption option enabled (specifying a KMS key), and then restore a new DB instance from the encrypted snapshot. This produces an encrypted instance containing the same data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the KMS key associated with the DB instance

    Why it's wrong here

    An unencrypted RDS instance has no KMS key associated with it, so there is nothing to 'change' — KMS keys are only attached when encryption is enabled at creation or via snapshot restore. Additionally, RDS does not support in-place modification of the KMS key for an existing instance; even for encrypted instances, you must restore from a snapshot to use a different key. Therefore, this action would not enable encryption at rest on the existing instance.

  • ✗

    Modify the DB instance to use an encrypted storage type

    Why it's wrong here

    RDS storage types (e.g., General Purpose SSD, Provisioned IOPS) are not themselves encrypted or unencrypted — encryption-at-rest is a property of the DB instance and its underlying volume, selected at launch. The 'Modify DB instance' operation can adjust storage size, type, or IOPS, but it cannot toggle encryption on an existing instance. Even converting to an encrypted volume type would not encrypt existing data; only a snapshot copy with encryption and restore can do that.

  • ✓

    Create a snapshot of the DB instance, copy it with encryption, and restore the encrypted snapshot

    Why this is correct

    To enable encryption-at-rest on an existing unencrypted Amazon RDS DB instance, you must create a manual snapshot, make an encrypted copy of that snapshot (either with the default AWS-managed key or a customer-managed KMS key), and then restore a new DB instance from the encrypted snapshot. During the snapshot copy you can also specify a KMS key; the restored instance will be encrypted, and you can then update your applications' connection strings to point to the new endpoint. This is the documented and only supported approach, since encryption cannot be added in place.

  • ✗

    Enable encryption at rest in the RDS console for the existing DB instance

    Why it's wrong here

    The RDS console does not offer a setting to turn on 'encryption at rest' for an already-provisioned instance; the encryption toggle is only presented at instance creation time (or when restoring from a snapshot). Attempting to modify the instance in the console reveals no such field, because AWS does not support in-place encryption enablement. If you need encrypted storage, you must follow the snapshot-copy-restore workflow rather than expecting a console checkbox to flip the encryption state.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.