nerdexam
AmazonAmazon

DBS-C01 · Question #28

DBS-C01 Question #28: Real Exam Question with Answer & Explanation

Sign in or unlock DBS-C01 to reveal the answer and full explanation for question #28. The question stem and answer options stay visible for context.

Submitted by tunde_lagos· Mar 6, 2026Database Security

Question

A company is running a two-tier ecommerce application in one AWS account. The web server is deployed using an Amazon RDS for MySQL Multi-AZ DB instance. A Developer mistakenly deleted the database in the production environment. The database has been restored, but this resulted in hours of downtime and lost revenue. Which combination of changes in existing IAM policies should a Database Specialist make to prevent an error like this from happening in the future? (Choose three.)

Options

  • AGrant least privilege to groups, users, and roles
  • BAllow all users to restore a database from a backup that will reduce the overall downtime to
  • CEnable multi-factor authentication for sensitive operations to access sensitive resources and API
  • DUse policy conditions to restrict access to selective IP addresses
  • EUse AccessList Controls policy type to restrict users for database instance deletion
  • FEnable AWS CloudTrail logging and Enhanced Monitoring

Unlock DBS-C01 to see the answer

You've previewed enough free DBS-C01 questions. Unlock DBS-C01 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#IAM#Database Security#Least Privilege#MFA
Full DBS-C01 PracticeBrowse All DBS-C01 Questions