AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityMedium
A healthcare organization stores sensitive patient data in an Amazon RDS for PostgreSQL database. Due to strict compliance regulations, they must ensure that all connections to the database are encrypted and that the database is not publicly accessible. They also need to implement a strong authentication mechanism. Which set of configurations should be applied to meet these requirements?
- AConfigure the RDS instance in a public subnet, rely on Security Groups for access control, and use native PostgreSQL password authentication.
- BConfigure the RDS instance in a public subnet, enable SSL/TLS for client connections, and use IAM database authentication.
- CConfigure the RDS instance in private subnets, enable SSL/TLS for client connections, and use native PostgreSQL password authentication.
- DConfigure the RDS instance in private subnets, enable SSL/TLS for client connections, and use IAM database authentication.
Show answer & explanationAnswer & explanation
Correct answer: D. Configure the RDS instance in private subnets, enable SSL/TLS for client connections, and use IAM database authentication.
Placing the RDS instance in private subnets ensures it's not publicly accessible. Enabling SSL/TLS encrypts all data in transit. IAM database authentication provides a more secure and auditable method of authentication than native password authentication, leveraging AWS IAM policies.
Why the other options are wrong
- A. Configuring RDS in a public subnet violates the 'not publicly accessible' requirement. Relying solely on Security Groups for access control is insufficient for preventing public exposure without private subnets, and native password authentication is less secure.
- B. Configuring RDS in a public subnet violates the 'not publicly accessible' requirement, even with SSL/TLS and IAM authentication.
- C. While private subnets and SSL/TLS are correct, native PostgreSQL password authentication is generally less secure and auditable compared to IAM database authentication for managing access.
Secure RDS Configuration
Best practices for securing Amazon RDS instances involve network isolation, in-transit encryption, and robust authentication mechanisms.
- Private subnets for network isolation.
- SSL/TLS for in-transit encryption.
- IAM database authentication for strong access control.
Memory trick: RDS: Private Network, Encrypted Data, IAM Power!