SCS-C02 Data Protection Practice Question
A security engineer is troubleshooting an issue where an Amazon RDS for MySQL DB instance is not encrypting data at rest. The DB instance was created without encryption. The engineer needs to enable encryption without significant downtime. What is the MOST effective approach?
⚠ Common exam trap
SCS-C02 often tests the misconception that you can enable encryption on an existing RDS instance via modification; candidates may select option C, not realizing encryption must be set at creation or via snapshot restore.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Take a snapshot, copy it with encryption enabled, and restore a new DB instance from the encrypted snapshot
To enable encryption on an unencrypted RDS DB instance with minimal downtime, you must take a snapshot, copy it with encryption enabled, and then restore a new DB instance from the encrypted snapshot. This creates a new encrypted instance, and you can then switch applications to it. The process requires some downtime during the switch, but it's the most effective method because RDS does not support enabling encryption in-place on an existing unencrypted instance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Take a snapshot of the DB instance and enable encryption on the snapshot
Why it's wrong here
An existing RDS snapshot is immutable with respect to encryption; there is no console action or API call to take a current snapshot and directly apply a KMS encryption key to that snapshot object. The only way to convert an unencrypted snapshot into an encrypted one is to create a new snapshot by copying it and specifying a KMS key during the copy operation. Attempting to 'enable encryption' on an existing snapshot will not change any data.
- ✓
Take a snapshot, copy it with encryption enabled, and restore a new DB instance from the encrypted snapshot
Why this is correct
Take a manual snapshot of the unencrypted DB instance, then use the AWS CLI or console to copy that snapshot into a new snapshot encrypted with a KMS key (for example, with the copy-db-snapshot command and a --kms-key-id parameter). Once the encrypted snapshot is available, restore a new DB instance from it. The restored instance inherits the encrypted storage from the snapshot, and after updating the application connection string to the new endpoint, the original unencrypted instance can be decommissioned.
- ✗
Modify the DB instance and enable encryption in the console
Why it's wrong here
Amazon RDS does not support enabling encryption on an existing unencrypted DB instance through an in-place modification. The Modify DB instance page in the console lacks an 'Enable encryption' toggle because encryption-at-rest settings are fixed at provisioning time; modifying the instance class, storage, or security groups will not change the encryption state. The only supported paths are restoring from an encrypted snapshot or building a new encrypted instance from scratch.
- ✗
Create a read replica with encryption and promote it
Why it's wrong here
A read replica inherits the encryption configuration of its source DB instance, so an unencrypted source can only produce an unencrypted replica; RDS will not allow a KMS key to be specified for a replica of an unencrypted primary. Even if you promote that replica later, the promoted instance will remain unencrypted. Replication therefore cannot be used as a workaround to add encryption to an existing deployment.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.