Courseiva
Infrastructure Security →mediumMultiple Select

SCS-C02 Infrastructure Security Practice Question

Which TWO actions can be taken to improve the security of an Amazon RDS for MySQL database instance? (Choose TWO.)

⚠ Common exam trap

It's easy for candidates to confuse high availability (Multi-AZ) or cost-saving measures (disabling backups) with security controls, when in fact they do not address confidentiality, integrity, or access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Place the RDS instance in a private subnet and restrict inbound traffic to the application security group.

Option A is correct because placing the RDS for MySQL instance in a private subnet removes it from direct internet reachability, and restricting inbound traffic to only the application's security group enforces least-privilege network access at the database port (3306 for MySQL). Option E is correct because enabling encryption at rest with AWS KMS protects the underlying storage, automated backups, read replicas, and snapshots, so data cannot be read if the storage media is compromised. Option B is incorrect because disabling automated backups reduces recoverability and does not improve security. Option C is incorrect because Multi-AZ is a high-availability/fault-tolerance feature, not a security control. Option D is incorrect because assigning a public IP address exposes the database to the internet and increases the attack surface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Place the RDS instance in a private subnet and restrict inbound traffic to the application security group.

    Why this is correct

    Placing the RDS instance in a private subnet removes any route to an internet gateway, so it cannot be reached directly from the internet. Restricting inbound rules to the application's security group enforces least-privilege access, permitting only the application tier on the MySQL port.

  • ✗

    Disable automated backups to reduce storage costs.

    Why it's wrong here

    Disabling automated backups removes point-in-time recovery, so a compromised or corrupted instance cannot be restored to a pre-incident state — directly weakening resilience rather than security. It is tempting because automated backup storage does carry cost, and disabling them suits disposable development or test databases where data loss is acceptable.

  • ✗

    Enable Multi-AZ deployment for fault tolerance.

    Why it's wrong here

    Multi-AZ provides availability, not security: it maintains a synchronous standby in another Availability Zone for failover. It is the right choice for resilience against AZ outages, but it neither encrypts data nor restricts network access, so it does not improve security posture.

  • ✗

    Assign a public IP address to the RDS instance for easier access from the internet.

    Why it's wrong here

    A public IP exposes the database directly to internet scanning and brute-force attempts, widening the attack surface. Public access is chosen when external clients must connect without a VPN or bastion, but here it directly undermines the security objective.

  • ✓

    Enable encryption at rest using AWS KMS.

    Why this is correct

    Enabling encryption at rest with AWS KMS protects the underlying storage volumes, automated backups, read replicas and snapshots, so data remains unreadable if the media is compromised. This satisfies the requirement to improve security of stored database content.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.