AWS Certified Developer – Associate (DVA-C02)SecurityEasy
A developer is creating a new application that needs to securely communicate with an Amazon RDS PostgreSQL database instance. The application requires that all data exchanged between the application and the database is encrypted in transit. The application is deployed on an EC2 instance within the same VPC as the RDS instance. Which configuration should the developer implement to ensure in-transit encryption?
- AEnable encryption at rest for the RDS instance using KMS.
- BUse an AWS PrivateLink endpoint to connect to the RDS instance.
- CConfigure the application to use SSL/TLS for the database connection.
- DEnsure the EC2 security group allows traffic on port 5432 (PostgreSQL default).
Show answer & explanationAnswer & explanation
Correct answer: C. Configure the application to use SSL/TLS for the database connection.
To ensure data is encrypted in transit between an application and an RDS PostgreSQL instance, the application must be configured to use SSL/TLS for its database connection. RDS supports SSL/TLS, and the application's database driver needs to be set up to enable it.
Why the other options are wrong
- A. Encryption at rest using KMS encrypts data stored on the database's disk, but not data in transit.
- B. AWS PrivateLink provides private connectivity between VPCs and services but does not inherently encrypt the traffic; SSL/TLS is still needed for in-transit encryption at the application layer.
- D. Allowing traffic on port 5432 is necessary for connectivity but does not, by itself, enforce encryption in transit.
RDS In-Transit Encryption (SSL/TLS)
To encrypt data in transit between an application and an Amazon RDS database, the application must be configured to establish an SSL/TLS connection to the database endpoint.
- RDS supports SSL/TLS for all database engines.
- Application's database driver needs to be configured for SSL/TLS.
- Protects data from eavesdropping during network transmission.
Memory trick: SSL/TLS Secures RDS Traffic.