AWS Certified SysOps Administrator – AssociateSecurity and ComplianceEasy

A company is deploying a new web application on AWS that will handle sensitive customer data. The security team has mandated that all data in transit between the application servers and the database must be encrypted. The database is hosted on Amazon RDS for PostgreSQL. Which AWS service or feature should the SysOps administrator use to ensure this requirement is met with minimal operational overhead?

  1. AUse AWS KMS to encrypt the data at rest on the RDS instance.
  2. BImplement client-side encryption for all data before sending it to the RDS instance.
  3. CConfigure a Site-to-Site VPN connection between the EC2 instances and the RDS instance.
  4. DEnable SSL/TLS encryption for the Amazon RDS for PostgreSQL instance.
Show answer & explanation

Correct answer: D. Enable SSL/TLS encryption for the Amazon RDS for PostgreSQL instance.

Enabling SSL/TLS encryption for Amazon RDS for PostgreSQL instances ensures that all data in transit between the client application and the database is encrypted. This is a built-in feature of RDS with minimal operational overhead.

Why the other options are wrong

  • A. AWS KMS for data at rest encrypts data stored on the database, but does not address data encryption "in transit."
  • B. Client-side encryption handles data before it leaves the client, but the question specifically asks for encryption "in transit" between application and database, which SSL/TLS handles more efficiently at the connection level.
  • C. Site-to-Site VPN is typically used for connecting on-premises networks to AWS, not for encrypting traffic between services within AWS.

RDS SSL/TLS Encryption

Amazon RDS supports SSL/TLS to encrypt connections between your application and your database instances, securing data in transit.

  • Encrypts data between client and RDS instance.
  • Uses standard SSL/TLS protocols.
  • Configured at the RDS instance level.

Memory trick: Transit means travel, so encrypt the connection's tunnel.

More Security and Compliance questions