A new workload uses an Amazon RDS for MySQL Multi-AZ database. The company requires all data at rest to be encrypted and keys to be rotated annually. Which configuration satisfies these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a customer managed AWS KMS key, enable automatic rotation for the key, and enable RDS encryption at DB creation using that KMS key..
Why this is the answer
The correct option ensures both encryption at rest and automatic annual key rotation. Enabling RDS encryption at database creation with a customer-managed AWS KMS key (CMK) encrypts the underlying storage. Configuring automatic key rotation for the CMK in AWS KMS satisfies the annual rotation requirement. Transparent Data Encryption (TDE) is not natively supported by Amazon RDS for MySQL. Enabling RDS encryption with an AWS-managed key for Amazon RDS does encrypt data at rest, but AWS-managed keys have a rotation period of over three years, not annually, and this rotation cannot be controlled by the user. Encrypting only the EBS volumes attached to the RDS instance is insufficient; RDS encryption must be enabled at the DB instance level to encrypt all data at rest, including backups and replicas.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed