SCS-C02 RDS Encryption at Rest Practice Question
A security engineer needs to ensure that an Amazon RDS for MySQL database is encrypted at rest. Which action should be taken?
⚠ Common exam trap
The trap here is assuming RDS supports in-place encryption toggling like some other AWS services; candidates often pick 'enable encryption on existing instance' because it sounds operationally convenient, but RDS requires instance recreation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a new DB instance with encryption enabled.
Amazon RDS does not support enabling encryption on an existing unencrypted DB instance. Encryption at rest must be configured at instance creation time by selecting the KMS key. Therefore, the only valid path is to create a new DB instance with encryption enabled and migrate data to it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a client-side encryption tool to encrypt data before writing to the database.
Why it's wrong here
Client-side encryption tools (e.g., the AWS Encryption SDK) encrypt data in the application before it is written to the database, but they do not encrypt the RDS instance's underlying storage or database files at rest. While this approach can protect sensitive individual column values, it requires application-level key management and modifies query behavior, making it impractical as a substitute for native instance-level encryption. The requirement for Amazon RDS encryption at rest is satisfied by enabling RDS storage encryption, not by adding a separate client-side layer.
- ✗
Use AWS KMS to encrypt individual databases within the instance.
Why it's wrong here
AWS KMS keys are used to encrypt the storage of the entire RDS DB instance, not individual databases or schemas hosted within that instance. When encryption is enabled, all databases on the instance share the same encrypted underlying storage and are protected by the same customer master key (CMK); you cannot assign a separate KMS key to a single database or schema. RDS encryption is an instance-level attribute, so selecting a KMS key to encrypt individual databases is not a supported configuration.
- ✗
Enable encryption on an existing unencrypted DB instance.
Why it's wrong here
Enabling encryption is a one-way setting that must be specified at instance creation; Amazon RDS does not provide a console, CLI, or API operation to turn on encryption for an existing unencrypted DB instance. The only supported migration path is to take a snapshot of the unencrypted instance, copy that snapshot with encryption enabled, and restore it to a new encrypted DB instance. Simply attempting to enable encryption directly on the existing instance fails, so this option cannot meet the requirement.
- ✓
Create a new DB instance with encryption enabled.
Why this is correct
Creating a new DB instance with encryption enabled is the correct approach because RDS encryption at rest is enabled at launch using an AWS KMS customer managed key. Once enabled, Amazon RDS transparently encrypts the underlying storage, automated backups, read replicas, and snapshots without requiring any application changes. After the new encrypted instance is created, migrate data from the existing source—either by restoring from an encrypted snapshot or using native database export/import tools—to complete the transition.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.