An RDS database running as a Multi-AZ DB instance failed a security audit because it is unencrypted. Which method will bring the database into compliance by enabling encryption?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a snapshot of the DB instance, copy and encrypt that snapshot, and restore a new encrypted DB instance from the encrypted snapshot..
Why this is the answer
You cannot directly enable encryption on an existing, unencrypted Amazon RDS DB instance. The correct method involves creating a snapshot of the unencrypted database. Then, you copy this snapshot and, during the copy process, you select the option to encrypt it. Finally, you restore a new RDS DB instance from this newly encrypted snapshot. This new DB instance will be encrypted at rest. The other options are incorrect because RDS encryption is applied at the instance level, not directly to EBS volumes attached to an RDS instance, nor can you encrypt only the standby replica and promote it. There is no direct "enable encryption" checkbox for an already provisioned unencrypted RDS instance.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed