SCS-C02 Infrastructure Security Practice Question
A security engineer is tasked with securing an Amazon RDS for MySQL database. The database must be accessible only from a specific set of EC2 instances. Which THREE steps should the engineer take?
⚠ Common exam trap
The trap here is that candidates may focus solely on network-level controls (security groups and subnets) and overlook encryption at rest as a required security step, or they may incorrectly believe that encryption at rest degrades performance significantly for MySQL workloads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable encryption at rest for the RDS instance.
Enabling encryption at rest for the RDS instance ensures that data stored on the underlying storage is encrypted using AWS Key Management Service (KMS). This is a security best practice for protecting sensitive data at rest, and it does not conflict with the requirement to restrict network access. Encryption at rest is independent of network access controls and is essential for compliance with many security frameworks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable encryption at rest to improve performance.
Why it's wrong here
Disabling encryption at rest is wrong because Amazon RDS encrypts the underlying storage, automated backups, snapshots, and read replicas transparently using AES-256 keys managed through AWS KMS, with negligible performance impact for typical workloads. The storage-layer encryption engine operates without adding meaningful latency, so any performance gain from disabling it is marginal and does not outweigh the security and compliance risk. Additionally, if the instance is already encrypted, encryption cannot simply be turned off without restoring an unencrypted snapshot, so this action would expose sensitive data.
- ✓
Enable encryption at rest for the RDS instance.
Why this is correct
Enabling encryption at rest protects the database by encrypting data files in the underlying block storage, along with automated backups, snapshots, and read replicas, using an AWS KMS customer master key (AES-256). This satisfies compliance requirements such as PCI DSS or HIPAA and defends against theft of physical storage or unauthorized access to snapshots. Must be configured at instance creation time; to encrypt an existing unencrypted instance, you have to create an encrypted snapshot and restore from it.
- ✓
Launch the RDS instance in a private subnet.
Why this is correct
Launching the RDS instance in a private subnet ensures the database has no route to the internet gateway, so it cannot be reached directly from the public internet. Combined with tightly scoped security groups, this network isolation prevents external attackers from even attempting connections to the RDS endpoint, because the DB's network interface is not addressable from outside the VPC. A private subnet still allows the EC2 application instances in the same VPC to reach the database over the internal route.
- ✓
Create a security group that allows inbound traffic on port 3306 from the EC2 instances' security group.
Why this is correct
Creating a security group rule that allows inbound traffic on TCP port 3306 only from the EC2 instances' security group is a precise, identity-based access control. This rule uses a security group as the source, rather than a CIDR block, so any current or future instance attached to that security group can reach the database, while all other sources are implicitly denied. It follows the principle of least privilege and prevents a security group rule authorizing 0.0.0.0/0, which would expose the RDS port to everyone.
- ✗
Associate the RDS instance with a public subnet for easier access.
Why it's wrong here
Associating the RDS instance with a public subnet gives it a route to an internet gateway, and if combined with a permissive security group or public IP assignment, it becomes reachable from the internet on port 3306. This directly exposes the database to brute-force attacks, unauthorized access, and data exfiltration risks. Even if you restrict the source CIDR, a public subnet placement is an unnecessary exposure; the correct architecture is a private subnet with no internet route and strict security group references.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.