SCS-C02 Data Protection Practice Question
Which TWO of the following are valid methods to enforce encryption at rest for an Amazon RDS for PostgreSQL DB instance? (Choose 2.)
⚠ Common exam trap
The trap is thinking you can enable encryption on an existing instance or snapshot; encryption must be set at creation or via an encrypted snapshot copy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restore a DB instance from an encrypted snapshot
Option B is correct because restoring from an encrypted snapshot is a supported way to obtain an encrypted DB instance: you can encrypt a snapshot copy (or use an already encrypted snapshot) and restore it, producing a DB instance with encryption at rest enabled via KMS. Option E is correct because encryption at rest for Amazon RDS for PostgreSQL must be specified at creation time; when you create a new DB instance you can enable encryption, and the underlying storage, automated backups, read replicas, and snapshots are then encrypted with the selected AWS KMS key. Option A is not valid because you cannot enable encryption on an existing unencrypted RDS DB instance in place; you must create an encrypted copy/restore. Option C is not valid because you cannot take a snapshot of an unencrypted instance and simply 'enable encryption on the snapshot' in place; you must copy the snapshot with encryption enabled. Option D is not valid because an encrypted read replica cannot be created from an unencrypted source instance, so this method cannot enforce encryption at rest for the original unencrypted DB instance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable encryption on an existing unencrypted DB instance
Why it's wrong here
RDS encryption is a property that is set when the DB instance is initially provisioned; there is no console, CLI, or API operation that can enable encryption on a running instance. The instance must be recreated from an encrypted backup or newly provisioned with encryption enabled. Attempting to modify the instance's storage settings to add encryption will fail because the encryption attribute is immutable after launch.
- ✓
Restore a DB instance from an encrypted snapshot
Why this is correct
Restoring a DB instance from an encrypted snapshot creates a new instance that is automatically encrypted using the KMS key that encrypted the snapshot. This process preserves the data while transferring encryption settings to the restored instance, making it a valid method for both new deployments and migrations from existing encrypted data. You may optionally choose a different customer-managed key during the restore, but encryption is guaranteed to be enabled.
- ✗
Take a snapshot of the unencrypted instance and enable encryption on the snapshot
Why it's wrong here
A snapshot taken from an unencrypted DB instance is itself unencrypted, and you cannot modify the encryption state of an existing snapshot in place. To produce an encrypted copy, you must use the 'Copy snapshot' action and select an encryption key during that copy, which creates a new encrypted snapshot. Merely taking a snapshot and attempting to 'enable encryption' on it is not a supported operation.
- ✗
Create an encrypted read replica and promote it
Why it's wrong here
Read replicas inherit the encryption configuration—including the KMS key—from their source DB instance, so you cannot create an encrypted read replica if the source is unencrypted. Promoting a read replica simply detaches it from the source cluster, but does not alter the encryption state of the instance. Thus, this method cannot enforce encryption on an existing unencrypted database.
- ✓
Create a new encrypted DB instance from the start
Why this is correct
When launching a new RDS instance, you can enable encryption at provisioning time by specifying an AWS KMS key in the console, CLI, or API. The instance, its automated backups, and snapshots are all encrypted using that key, making this the most direct way to enforce encryption for a newly created database. Once the instance exists, encryption cannot be enabled retroactively, so this must be decided at launch.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.