QuestionQ1

Infrastructure Security

A company must comply with a requirement to encrypt all data in transit. The company recently identified an Amazon Aurora cluster that fails to meet this requirement.

How can the company require encryption for every connection to the Aurora cluster?

Explanation

Setting the Aurora MySQL DB cluster parameter require_secure_transport to ON requires TLS for user connections and rejects clients that cannot establish an encrypted connection. This directly enforces encryption of data in transit for connections to the cluster.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!