List of questions
Related questions
Question 260 - DBS-C01 discussion
A company has a database fleet that includes an Amazon RDS for MySQL DB instance. During an audit, the company discovered that the data that is stored on the DB instance is unencrypted.
A database specialist must enable encryption for the DB instance. The database specialist also must encrypt all connections to the DB instance.
Which combination of actions should the database specialist take to meet these requirements?
(Choose three.)
A.
In the RDS console, choose ? “Enable encryption ?” to encrypt the DB instance by using an AWS Key Management Service (AWS KMS) key.
B.
Encrypt the read replica of the unencrypted DB instance by using an AWS Key Management Service (AWS KMS) key. Fail over the read replica to the primary DB instance.
C.
Create a snapshot of the unencrypted DB instance. Encrypt the snapshot by using an AWS Key Management Service (AWS KMS) key. Restore the DB instance from the encrypted snapshot. Delete the original DB instance.
D.
Require SSL connections for applicable database user accounts.
E.
Use SSL/TLS from the application to encrypt a connection to the DB instance.
F.
Enable SSH encryption on the DB instance.
Your answer:
0 comments
Sorted by
Leave a comment first