Courseiva
Infrastructure Security →hardMultiple Select

SCS-C02 Infrastructure Security Practice Question

Which THREE of the following are best practices for securing an Amazon RDS database instance? (Select THREE.)

⚠ Common exam trap

Many candidates confuse 'public accessibility' with necessary management access, but AWS explicitly recommends placing RDS in a private subnet and using a bastion host or AWS Systems Manager Session Manager for secure administrative access, not a public IP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable encryption at rest using AWS KMS

Enabling encryption at rest using AWS KMS ensures that the underlying storage for the RDS instance, automated backups, read replicas, and snapshots are encrypted using AES-256. This protects data at rest from unauthorized physical access or storage media theft, and is a fundamental security best practice for compliance frameworks like PCI DSS and HIPAA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable encryption at rest using AWS KMS

    Why this is correct

    RDS encryption at rest uses AWS KMS envelope encryption, where a customer master key (CMK) encrypts the data keys that encrypt your database storage, automated backups, snapshots, and read replicas. If the underlying EBS volumes are compromised, the encrypted data remains unreadable without KMS key access, and you also get a compliance benefit. Note that you must enable encryption at launch because you cannot encrypt an existing unencrypted RDS instance in place.

  • ✓

    Place the RDS instance in a private subnet

    Why this is correct

    Launching RDS in a private subnet ensures the instance has no public IP address, so the database cannot be reached directly from the internet. Instead, applications connect through a bastion host, VPN, or VPC peering, forcing traffic through paths you control. Even with a security group allowing 0.0.0.0/0, a private subnet effectively blocks inbound internet traffic at the network layer, shrinking the attack surface.

  • ✓

    Use strong passwords and rotate them regularly

    Why this is correct

    The RDS master user password is a primary authentication factor, and weak or rarely rotated passwords are vulnerable to brute-force and credential-stuffing attacks. AWS Secrets Manager can automate rotation for RDS, updating credentials while your application safely retrieves the latest version via the API. Rotation limits the window of exposure if a password is ever leaked, and strong passwords with length/complexity make guessing infeasible.

  • ✗

    Enable public accessibility for ease of management

    Why it's wrong here

    Setting PubliclyAccessible=true gives the RDS instance a public IP and routes it through internet gateways, exposing your database endpoint to the entire internet. That expansion of the attack surface makes the instance a direct target for scans, SQL injection exploits, and login brute force before any security group even filters traffic. Management should instead be handled via a bastion host, SSM Session Manager, or an AWS VPN, never by opening the database to the public network.

  • ✗

    Use the default database port

    Why it's wrong here

    Default ports such as 3306 for MySQL, 5432 for PostgreSQL, and 1433 for SQL Server are widely known and continuously scanned by automated bots, so keeping them makes your RDS endpoint easier to discover unintentionally. Changing to a non-standard port is a useful form of security through obscurity because it reduces opportunistic attacks, though it does not stop a determined attacker who can port-scan. RDS still requires the port to be explicitly opened in the security group, but using a custom port is still a better hardening practice.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.