AWS Certified SysOps Administrator – AssociateSecurity and ComplianceMedium
A company is using Amazon RDS for PostgreSQL databases to store sensitive customer data. Due to compliance requirements, all connections to the database must be encrypted in transit. Additionally, the company needs to ensure that only authenticated clients can connect to the database. What is the MOST secure way to meet these requirements?
- AEncrypt the data at rest using KMS and manage user credentials with AWS Secrets Manager.
- BConfigure security groups to only allow connections from specific IP addresses.
- CEnable SSL/TLS for all RDS connections and configure client applications to enforce SSL/TLS.
- DUse IAM database authentication for PostgreSQL and enable SSL/TLS for connections.
Show answer & explanationAnswer & explanation
Correct answer: D. Use IAM database authentication for PostgreSQL and enable SSL/TLS for connections.
IAM database authentication provides a more secure and granular way to manage database access by using IAM users and roles, eliminating the need for traditional database credentials. Combined with SSL/TLS, it ensures both in-transit encryption and strong client authentication.
Why the other options are wrong
- A. Encrypting data at rest (KMS) and managing credentials (Secrets Manager) are important for overall security but do not directly address the in-transit encryption and client authentication for database connections.
- B. Security groups control network access but do not provide encryption in transit or strong client authentication at the database level.
- C. Enabling SSL/TLS addresses in-transit encryption, but it doesn't inherently provide a robust client authentication mechanism beyond traditional database credentials, which can be less secure than IAM.
RDS IAM Database Authentication + SSL/TLS
IAM database authentication allows you to authenticate to your Amazon RDS database instance using AWS IAM. This provides a more secure and centralized way to manage database access. Combining it with SSL/TLS ensures both strong client authentication and encrypted communication in transit.
- Uses IAM users/roles for database authentication.
- Eliminates need for traditional database credentials.
- SSL/TLS encrypts data in transit.
- Provides fine-grained access control.
Memory trick: IAM + SSL: Secure RDS Connections.