SCS-C02 Infrastructure Security Practice Question
Which TWO actions can be taken to improve the security of an Amazon RDS for MySQL database instance? (Choose TWO.)
⚠ Common exam trap
It's easy for candidates to confuse high availability (Multi-AZ) or cost-saving measures (disabling backups) with security controls, when in fact they do not address confidentiality, integrity, or access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place the RDS instance in a private subnet and restrict inbound traffic to the application security group.
Option A is correct because placing the RDS for MySQL instance in a private subnet removes it from direct internet reachability, and restricting inbound traffic to only the application's security group enforces least-privilege network access at the database port (3306 for MySQL). Option E is correct because enabling encryption at rest with AWS KMS protects the underlying storage, automated backups, read replicas, and snapshots, so data cannot be read if the storage media is compromised. Option B is incorrect because disabling automated backups reduces recoverability and does not improve security. Option C is incorrect because Multi-AZ is a high-availability/fault-tolerance feature, not a security control. Option D is incorrect because assigning a public IP address exposes the database to the internet and increases the attack surface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Place the RDS instance in a private subnet and restrict inbound traffic to the application security group.
Why this is correct
Placing the RDS instance in a private subnet removes any route to an internet gateway, so it cannot be reached directly from the internet. Restricting inbound rules to the application's security group enforces least-privilege access, permitting only the application tier on the MySQL port.
- ✗
Disable automated backups to reduce storage costs.
Why it's wrong here
Disabling automated backups removes point-in-time recovery, so a compromised or corrupted instance cannot be restored to a pre-incident state — directly weakening resilience rather than security. It is tempting because automated backup storage does carry cost, and disabling them suits disposable development or test databases where data loss is acceptable.
- ✗
Enable Multi-AZ deployment for fault tolerance.
Why it's wrong here
Multi-AZ provides availability, not security: it maintains a synchronous standby in another Availability Zone for failover. It is the right choice for resilience against AZ outages, but it neither encrypts data nor restricts network access, so it does not improve security posture.
- ✗
Assign a public IP address to the RDS instance for easier access from the internet.
Why it's wrong here
A public IP exposes the database directly to internet scanning and brute-force attempts, widening the attack surface. Public access is chosen when external clients must connect without a VPN or bastion, but here it directly undermines the security objective.
- ✓
Enable encryption at rest using AWS KMS.
Why this is correct
Enabling encryption at rest with AWS KMS protects the underlying storage volumes, automated backups, read replicas and snapshots, so data remains unreadable if the media is compromised. This satisfies the requirement to improve security of stored database content.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.