A development team is building a new application that will use Amazon RDS for its database. The security team has mandated that all connections to the RDS database must be encrypted in transit. The application will be deployed on EC2 instances within the same VPC as the RDS instance. How can the developer ensure that the application uses SSL/TLS for all connections to the RDS database?
- AEncrypt the data at the application layer before sending it to RDS.
- BEnable SSL/TLS certificates on the RDS instance and configure the application to enforce SSL/TLS connections.
- CUse an AWS Network Load Balancer (NLB) in front of the RDS instance to terminate SSL/TLS.
- DConfigure the RDS security group to only allow HTTPS traffic.
Show answer & explanationAnswer & explanation
Correct answer: B. Enable SSL/TLS certificates on the RDS instance and configure the application to enforce SSL/TLS connections.
To ensure encrypted connections in transit to RDS, SSL/TLS must be enabled on the RDS instance (which is typically enabled by default or easily configurable) and, crucially, the application's database client must be configured to *enforce* SSL/TLS connections. This ensures that all communication between the application and RDS is encrypted.
Why the other options are wrong
- A. Encrypting data at the application layer is client-side encryption for data at rest, not encryption in transit for the database connection itself.
- C. NLB can terminate SSL/TLS, but placing it in front of RDS is not a standard or recommended pattern for direct application-to-database connections and adds unnecessary complexity for in-transit encryption.
- D. RDS uses specific database port numbers (e.g., 3306 for MySQL, 5432 for PostgreSQL), not HTTPS (port 443), for database connections. Security groups control ports, not encryption enforcement.
RDS SSL/TLS Encryption
Amazon RDS supports SSL/TLS to encrypt connections between the application and the database instance. This requires enabling SSL/TLS on the RDS instance and configuring the client application to enforce encrypted connections.
- Encrypts data in transit to RDS
- Requires SSL/TLS on RDS instance
- Application client must enforce SSL/TLS
Memory trick: RDS connections need SSL/TLS on both ends.