AWS Certified Developer – Associate (DVA-C02)SecurityEasy
A development team is deploying a new microservice on AWS Fargate. This microservice needs to access an Amazon RDS PostgreSQL database. The security team has mandated that all connections to the database must be encrypted using SSL/TLS to protect data in transit. How can the developer ensure that the Fargate task establishes an SSL/TLS encrypted connection to the RDS database?
- AConfigure a VPC endpoint for RDS within the Fargate VPC.
- BDeploy an AWS Client VPN endpoint and route all database traffic through it.
- CUse an AWS Secrets Manager secret to store the database credentials and force SSL/TLS.
- DEnable SSL/TLS on the RDS database instance and configure the application to enforce SSL/TLS.
Show answer & explanationAnswer & explanation
Correct answer: D. Enable SSL/TLS on the RDS database instance and configure the application to enforce SSL/TLS.
To ensure SSL/TLS encryption for RDS connections, you must enable SSL/TLS on the RDS database instance itself and then configure the client application (running on Fargate) to enforce SSL/TLS when connecting. This ensures data is encrypted in transit.
Why the other options are wrong
- A. VPC endpoints provide private connectivity but do not inherently enforce SSL/TLS encryption for database connections.
- B. Client VPN is for connecting client networks to AWS, not for encrypting internal application-to-database traffic within a VPC.
- C. Secrets Manager stores credentials securely but does not directly enforce SSL/TLS for database connections; the application still needs to be configured.
RDS SSL/TLS Encryption
Amazon RDS supports SSL/TLS to encrypt connections between your application and your database instances, protecting data in transit. Both the database instance and the client application must be configured to use SSL/TLS.
- Protects data in transit between client and database.
- Requires enabling SSL/TLS on the RDS instance.
- Requires the client application to enforce SSL/TLS for connections.
- Can use a CA certificate for certificate validation.
Memory trick: RDS SSL/TLS: Server and Client must agree to encrypt the data journey.