A FinTech companu is running web application on an Amazon RDS for MariaDB instance in Multi-AZ deployment setup. They want to achieve regulatory compliance. Currently, RDS DB instance is associated with a DB subnet group with private subnets without an Internet gateway. Howeverr, it is configured with security groups to allow traffic in and out of application servers only.

The Master key used to encrypt database at rest is managed using AWS KMS. How can this setup have new and enhanced security?

Set up NACLs that allow the entire EC2 subnet to access DB instance
Turn off Public accessibility of RDS DB instance
Create a new rule in security group that denies port 22 traffic to RDS DB instance
Enable SSL in RDS DB instance and encrypt data in transit.
Verified Answer
Correct Option - d

To get all Infosys Certified AWS Database Specialty Exam questions Join Telegram Group https://rebrand.ly/lex-telegram-236dee

Telegram