SOA-C02 Security and Compliance Practice Question
A SysOps administrator needs to ensure that an Amazon RDS instance is encrypted at rest. The instance is already provisioned unencrypted. What is the correct approach to enable encryption?
⚠ Common exam trap
SOA-C02 often tests the misconception that modify-db-instance can enable encryption — candidates must remember RDS encryption is immutable after creation and requires snapshot-restore.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a snapshot of the instance and restore it with encryption enabled
RDS does not allow enabling encryption in place on an existing unencrypted instance. The supported path is to snapshot the instance, then restore that snapshot with encryption enabled, which produces a new encrypted instance. You then repoint applications to the new endpoint.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a snapshot of the instance and restore it with encryption enabled
Why this is correct
The only supported way to add encryption to an existing Amazon RDS instance is to create a manual snapshot, copy that snapshot with a KMS customer master key (encryption enabled), and then restore a new DB instance from the encrypted copy. Encryption is a creation-time attribute, so this snapshot-and-restore workflow effectively rebuilds the database with at-rest encryption while preserving your data and configuration.
- ✗
Use AWS KMS to encrypt the underlying EBS volumes of the RDS instance
Why it's wrong here
Amazon RDS does not expose its underlying EBS volumes to the customer, and there is no API to directly encrypt those volumes. When you enable RDS encryption, it is applied at the RDS engine/storage layer using AWS KMS, not by separately encrypting EBS volumes in your account. Attempting to use KMS to encrypt EBS volumes outside the RDS service is conceptually invalid because the volumes are managed entirely by RDS.
- ✗
Enable encryption using the AWS CLI command modify-db-instance
Why it's wrong here
The AWS CLI modify-db-instance command updates certain settings on an existing DB instance—such as allocated storage, instance class, or backup retention—but it has no parameter to enable or alter storage encryption. RDS architecture simply does not allow in-place encryption changes, so any attempt to use this command to add encryption will fail or be ignored. You must instead use snapshot-and-restore to achieve encryption.
- ✗
Modify the RDS instance and enable encryption in the configuration
Why it's wrong here
The RDS Management Console does not provide a toggle to enable encryption after an instance has been created. When you select an existing instance and choose to modify it, the encryption settings are not present because encryption must be specified only at launch time. Editing the configuration in the console cannot circumvent this limitation; the instance must be recreated from an encrypted snapshot or created new with encryption enabled.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.