AWS Certified Developer – Associate (DVA-C02)SecurityMedium
A development team is deploying a new microservice on AWS Fargate. This microservice needs to interact with an Amazon RDS database instance. To ensure secure communication, the team wants to implement encryption in transit between the Fargate task and the RDS instance. Which configuration should the developer apply?
- AUse AWS PrivateLink to establish a private connection between Fargate and RDS.
- BConfigure the Fargate task definition to use HTTPS for database connections.
- CEnable SSL/TLS on the Amazon RDS database instance and configure the application to use SSL/TLS.
- DEnsure the Fargate task and RDS instance are in the same private subnet.
Show answer & explanationAnswer & explanation
Correct answer: C. Enable SSL/TLS on the Amazon RDS database instance and configure the application to use SSL/TLS.
To ensure encryption in transit for database connections, SSL/TLS must be enabled on the Amazon RDS instance and the application connecting to it must be configured to use SSL/TLS for its database connection string. This encrypts the data as it travels between the application and the database.
Why the other options are wrong
- A. AWS PrivateLink provides private connectivity, but SSL/TLS is still required at the application layer for encryption in transit over that private link.
- B. HTTPS is for web traffic, not typically for direct database connections. Database protocols use SSL/TLS.
- D. Being in the same private subnet provides network isolation but does not inherently encrypt data in transit.
RDS SSL/TLS Encryption
Enabling SSL/TLS on an Amazon RDS instance encrypts data in transit between the client application and the database, protecting it from eavesdropping.
- Encrypts data during transmission.
- Requires both server (RDS) and client (application) configuration.
- Uses X.509 certificates for authentication.
Memory trick: SSL/TLS keeps your database data safe on the wire.