SOA-C02 Security and Compliance Practice Question
A company stores sensitive data in an RDS database. Which AWS service should be used to encrypt the database at rest?
⚠ Common exam trap
SOA-C02 often tests the confusion between encryption in transit (ACM/TLS) and encryption at rest (KMS), so candidates who see 'certificate' or 'key' and pick ACM or CloudHSM instead of KMS lose the point.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Key Management Service (KMS)
AWS Key Management Service (KMS) is the AWS service that manages the customer master keys (CMKs) used to encrypt RDS databases at rest. When you enable encryption on an RDS instance, you select a KMS key, and RDS uses that key to encrypt the underlying storage, snapshots, and read replicas. KMS integrates natively with RDS, EBS, S3, and most other AWS services for at-rest encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Certificate Manager (ACM)
Why it's wrong here
AWS Certificate Manager (ACM) is designed to provision, manage, and renew public and private SSL/TLS certificates used to encrypt data in transit between clients and services such as Elastic Load Balancers, CloudFront, and API Gateway. ACM does not provide any mechanism for encrypting data stored in a database, nor does it integrate with RDS storage-level encryption. While TLS protects data as it moves across a network, it does nothing to protect data at rest in RDS, so ACM is not relevant to this requirement.
- ✗
AWS Identity and Access Management (IAM)
Why it's wrong here
IAM manages authentication and authorisation for user and service access, not data encryption at rest. It lacks any mechanism to encrypt database storage volumes or manage encryption keys. The temptation arises because IAM is often used to control access to encrypted resources, but in this scenario the requirement is for the encryption itself, which IAM cannot perform. For controlling which users can decrypt data, IAM would be correct.
- ✓
AWS Key Management Service (KMS)
Why this is correct
AWS Key Management Service (KMS) is a managed service for creating and controlling customer master keys (CMKs) that encrypt data at rest across AWS services, including Amazon RDS. When you enable encryption on an RDS instance, RDS uses a KMS CMK to encrypt the underlying EBS storage, automated backups, snapshots, and read replicas, with encryption handled transparently by the service. KMS is the only service among these options that natively integrates with RDS for at-rest encryption, making it the correct choice.
- ✗
AWS CloudHSM
Why it's wrong here
AWS CloudHSM provides dedicated, single-tenant hardware security modules (HSMs) that you fully control, allowing you to manage your own cryptographic keys inside a tamper-resistant appliance. However, Amazon RDS does not natively integrate with CloudHSM for encryption at rest; RDS encryption uses AWS KMS customer master keys (CMKs) to encrypt data, snapshots, and automated backups. To use CloudHSM with RDS, you would have to implement application-level encryption yourself, which is not the straightforward database-level encryption this scenario requires.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.