nerdexam
Amazon

DBS-C01 · Question #115

A company is running an Amazon RDS for MySQL Multi-AZ DB instance for a business-critical workload. RDS encryption for the DB instance is disabled. A recent security audit concluded that all…

The correct answer is C. Create a snapshot of the unencrypted DB instance. https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Overview.Encryption.html#Overvie w.Encryption.Limitations

Submitted by yousef_jo· Mar 6, 2026Database Security

Question

A company is running an Amazon RDS for MySQL Multi-AZ DB instance for a business-critical workload. RDS encryption for the DB instance is disabled. A recent security audit concluded that all business-critical applications must encrypt data at rest. The company has asked its database specialist to formulate a plan to accomplish this for the DB instance. Which process should the database specialist recommend?

Options

  • ACreate an encrypted snapshot of the unencrypted DB instance.
  • BCreate a new RDS for MySQL DB instance with encryption enabled.
  • CCreate a snapshot of the unencrypted DB instance.
  • DTemporarily shut down the unencrypted DB instance.

How the community answered

(20 responses)
  • A
    10% (2)
  • B
    5% (1)
  • C
    80% (16)
  • D
    5% (1)

Explanation

https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Overview.Encryption.html#Overvie w.Encryption.Limitations

Topics

#RDS encryption#data at rest encryption#snapshots#security audit#KMS

Community Discussion

No community discussion yet for this question.

Full DBS-C01 Practice