nerdexam
Amazon

SCS-C02 · Question #90

A company is building an application on AWS that will store sensitive information. The company has a support team with access to the IT infrastructure, including databases. The company's security engi

The correct answer is C. Enable Amazon RDS encryption to encrypt the database and snapshots. Enable Amazon Elastic. https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotate-secrets_turn-on-for-db.html

Submitted by fatema_kw· Mar 6, 2026Data Protection

Question

A company is building an application on AWS that will store sensitive information. The company has a support team with access to the IT infrastructure, including databases. The company's security engineer must introduce measures to protect the sensitive data against any data breach while minimizing management overhead. The credentials must be regularly rotated. What should the security engineer recommend?

Options

  • AEnable Amazon RDS encryption to encrypt the database and snapshots. Enable Amazon Elastic
  • BInstall a database on an Amazon EC2 instance. Enable third-party disk encryption to encrypt the
  • CEnable Amazon RDS encryption to encrypt the database and snapshots. Enable Amazon Elastic
  • DSet up an AWS CloudHSM cluster with AWS Key Management Service (AWS KMS) to store KMS

How the community answered

(65 responses)
  • A
    5% (3)
  • B
    6% (4)
  • C
    77% (50)
  • D
    12% (8)

Explanation

https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotate-secrets_turn-on-for-db.html

Topics

#Secrets Manager#credential rotation#RDS encryption#least privilege

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice