Courseiva
Security and Compliance →hardMultiple Select

SOA-C02 Security and Compliance Practice Question

A SysOps administrator needs to ensure that an Amazon RDS for MySQL database is compliant with PCI DSS requirements. Which THREE configurations should be implemented?

⚠ Common exam trap

Many candidates confuse Multi-AZ deployment (high availability) with a security or compliance control, but PCI DSS does not require high availability; it requires encryption, logging, and access controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Require SSL/TLS connections to the database.

Option B is correct because PCI DSS requires strong cryptography for data in transit, and enforcing SSL/TLS on RDS for MySQL (via the require_secure_transport parameter or rds.force_ssl) ensures all client connections are encrypted. Option D is correct because PCI DSS mandates audit trails and monitoring of access to cardholder data; RDS audit logging (e.g., MySQL audit or general/slow query logs exported to CloudWatch Logs) captures database activity for review and forensics. Option E is correct because PCI DSS requires protection of stored cardholder data, and enabling encryption at rest with AWS KMS encrypts the underlying storage, snapshots, and read replicas. Option A is not a PCI DSS requirement—Multi-AZ provides high availability, not compliance controls. Option C is not required by PCI DSS; while backups support availability and retention, the specific 30-day automated backup retention is not a PCI DSS mandate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Multi-AZ deployment for high availability.

    Why it's wrong here

    Multi-AZ deployment creates a synchronous standby replica in a different Availability Zone to provide automatic failover, but it does not add any encryption, access control, or logging capabilities. High availability ensures business continuity during an AZ outage; it does not protect cardholder data at rest or in transit, nor does it monitor access. Therefore, Multi-AZ alone does not satisfy any specific PCI DSS requirement.

  • ✓

    Require SSL/TLS connections to the database.

    Why this is correct

    Requiring SSL/TLS for all client connections to the RDS instance encrypts data during transmission, directly fulfilling PCI DSS Requirement 4.2.1, which mandates protecting cardholder data over open networks. By enforcing SSL/TLS at the database parameter group level, you prevent eavesdropping or man-in-the-middle attacks on queries and result sets. This is a foundational security control for any database that stores cardholder data.

  • ✗

    Configure automated backups with a retention period of 30 days.

    Why it's wrong here

    Automated backups with a 30-day retention address recoverability, but PCI DSS also requires encryption of data at rest and in transit plus audit logging of database activity, which a retention setting alone does not deliver. A 30-day retention window is the right configuration when the driver is a recovery point objective or a regulatory retention period for backup copies.

  • ✓

    Enable RDS audit logging to capture database activities.

    Why this is correct

    Enabling RDS audit logging captures detailed records of database connections, queries, and administrative actions, which is required by PCI DSS Requirement 10 to log and monitor all access to cardholder data. The logs can be exported to CloudWatch Logs for real-time analysis and alerting on suspicious activities. Without such logging, you cannot demonstrate compliance or perform forensic investigations after a potential breach.

  • ✓

    Enable encryption at rest using AWS KMS.

    Why this is correct

    Encrypting the RDS storage with AWS KMS protects cardholder data at rest, satisfying PCI DSS Requirement 3.4.1, which requires rendering stored account data unreadable. This encryption covers the underlying storage, automated backups, snapshots, and read replicas, ensuring that even if physical disks are compromised, the data remains indecipherable without the KMS keys. It is a mandatory control for PCI DSS compliance and complements encryption in transit.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.