> ## Documentation Index
> Fetch the complete documentation index at: https://cloud-architect.ipoint-labs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# How to Encrypt an Unencrypted RDS DB Instance

> Hands-on lab · 20m

Launch this lab in the IP Lab Portal, then follow the steps below in the AWS console.

<a className="ip-lab-portal-btn" href="https://labs.intellectualpoint.com/labs/how-to-encrypt-an-unencrypted-rds-db-instance" target="_blank" rel="noreferrer">
  Open IP Lab Portal
</a>

## Overview

### Lab Details

1. This lab walks you through the steps to create an unencrypted instance with the Encrypt option.
2. You will practice this lab by not enabling the encryption of DB Instance while creating.
3. Duration: **1 hour 20 minutes**
4. AWS Region: **US East (N. Virginia) us-east-1**

### Introduction

1. Amazon RDS can encrypt your Amazon RDS DB Instances.
2. When the encrypt option is enabled for the AWS RDS Resources, we are able to encrypt **DB Instances**, **Automated Backups**, **Read replicas**, **Snapshots** and **Logs**.
3. Amazon RDS encrypted DB instances use the AES-256 encryption algorithm to encrypt your data on the server that hosts your Amazon RDS DB instances.
4. The Encrypt option can be enabled only when you are launching the DB instance, it cannot be enabled after launch. However, copies of unencrypted snapshots can be encrypted.

### Architecture Diagram

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/001.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=aeacac598fa911c939c08886db93a1eb" alt="" width="1999" height="1345" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/001.png" />

### Task Details

1. Sign in to AWS Management Console.
2. Create an Amazon RDS DB Instance (without enabling encrypt option).
3. Take a snapshot from an existing DB Instance.
4. Make a copy of the snapshot and encrypt it.
5. Restore DB Instance from the encrypted snapshot.
6. Change the name of the original DB Instance.
7. Change the name of the Restored DB Instance to the original DB Instance name.
8. Delete the original RDS Instance and snapshot.
9. Deleting AWS Resources

### Case Study

1. Suppose we have created an RDS DB Instance without enabling the encryption. As days passed by the project became bigger and began to store more sensitive data.
2. As you are quite aware of security issues, you wanted to check on the AWS console that your database was well encrypted.
3. Your database was totally **Unencrypted**. And when you check to encrypt the database, you have **no option** to encrypt the database.

### Launching Lab Environment

1. To launch the lab environment, Click on the **Start Lab** button.
2. Please wait until the cloud environment is provisioned. It will take less than a minute to provision.
3. Once the Lab is started, you will be provided with **IAM user name**, **Password**, **Access** **Key**, and **Secret** **Access** **Key**.

> **Note** : You can only start one lab at any given time

## Lab guide

### Lab Steps

#### Task 1: Sign in to AWS Management Console

1. Click on the **Open Console** button, and you will get redirected to AWS Console in a new browser tab.
2. On the AWS sign-in page,

   * Leave the Account ID as default. Never edit/remove the 12 digit Account ID present in the AWS Console. otherwise, you cannot proceed with the lab.
   * Now copy your **User Name** and **Password** in the Lab Console to the **IAM Username and Password** in AWS Console and click on the **Sign in** button.
3. Once Signed In to the AWS Management Console, Make the default AWS Region as **US East (N. Virginia) us-east-1.**

#### Task 2: Create an RDS DB Instance (without enabling the Encryption)

1. Navigate to the **Services** menu at the top left corner and click on **RDS** present under the **Database** section.
2. Select the **Database** from the left panel.
3. Click on **Create Database** and you are navigated to the page where you will provide all the required details to create a MySQL database.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/002.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=83faa52160e10080a857c1a3c83ad3ea" alt="" width="1222" height="192" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/002.png" />

4. On the page, click on the option **Standard create** a method for our lab requirement.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/003.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=1bd2f9a186cad4a984450716bb7cd41f" alt="" width="1222" height="115" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/003.png" />

5. In the **Engine options**, select MySQL engine type.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/004.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=7a1a87f5b81d223ee22f9733bba07a5b" alt="" width="1222" height="427" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/004.png" />

6. **Edition**: Leave it as default

7. Under **Templates**, select the **Sandbox** option.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/005.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=6fa4ee8f88ca7db6623d2a0f4e819d4c" alt="" width="1222" height="138" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/005.png" />

8. Under Settings, provide the following details.

* DB cluster identifier: Enter ***test-db***
* ***Master username: Enter master***
* Credentials management: select **Self managed**
* Master password and Confirm master password: Enter ***Whizlabs123***

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/006.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=aee267b5fda79b45696b3c2f3ac05ecc" alt="" width="1222" height="504" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/006.png" />

9. Under **DB instance class**, select **Burstable classes (includes t classes)** and select **db.t3.micro**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/007.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=1872cb17d8bd8db5bb3b3f43c10ad7f4" alt="" width="1222" height="327" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/007.png" />

10. Storage type  : **General Purpose (SSD)**

* Allocated storage : **20**
* Uncheck **Enable storage autoscaling**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/008.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=10de8ae5d0297e2c44c9205ade87bd9a" alt="" width="1222" height="364" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/008.png" />

11. Leave the **Availability and durability** as default.

12. Under **Connectivity**, make sure that **Public access** is **No**. Leave everything else as default.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/009.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=a123962f96159563b93811b597b7f582" alt="" width="1222" height="144" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/009.png" />

13. Uncheck **Enhanced Monitoring** option.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/010.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=cca2fad6116741b4625dbf427f277d5b" alt="" width="1222" height="392" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/010.png" />

14. Expand the **Additional configuration**.

* Initial database name : Enter ***projectdb***
* Leave **DB parameter group** and **Option group** as default.
* Uncheck **Enable automatic backups**.
* Uncheck **Enable encryption** option.
* Uncheck **Deletion protection**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/011.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=2360200b5a47eddef5fc0ecd36fe7393" alt="" width="1222" height="776" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/011.png" />

15. Click on **Create Database** to create the database. This process does take time between 5-10 minutes.

16. Once the database is created the status changes to **Available**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/012.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=dfab867e6158bba178e2ee46dbf77391" alt="" width="1222" height="346" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/012.png" />

17. Click on the database and navigate to the **Configuration** tab. You can notice that the **Encryption** is **not enabled**, as we wanted it to be.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/013.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=de845be066f5b01d6370183875c324c7" alt="" width="1222" height="544" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/013.png" />

18. If we select the database and go to modify it, we will not find an option to Encrypt the database.

#### Task 3: Take a snapshot from the existing DB Instance

1. Select the created DB Instance and click on **Actions.**

2. Click **Take snapshot** from the options.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/014.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=a9295a4ae402f00bcda745b05dd86612" alt="" width="1222" height="496" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/014.png" />

3. Give a name to the snapshot, **test-snapshot-01** and click on the **Take snapshot** button.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/015.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=fe6627b608e30ebe8137e8ec921504bf" alt="" width="1222" height="431" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/015.png" />

4. The snapshot creation takes 3-5 minutes. Refresh after some time, the snapshot creation status will be **available**.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/016.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=82c4a1494ec9768d811ede1e61e87961" alt="" width="1222" height="405" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/016.png" />

#### Task 4: Make a copy of the snapshot and encrypt it

1. It is not possible to encrypt the snapshot in this stage. We need to encrypt the snapshot while taking a copy of it.

2. Under the **Manual snapshots**, select the created snapshot and click on **Actions**.

3. Click **Copy snapshot** from the options.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/017.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=6ed4d886cdc1948691bd689fa21faff8" alt="" width="1222" height="418" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/017.png" />

4. Under settings, provide the following details.

* New DB Snapshot Identifier: Enter **test-snapshot-encrypted**
* Destination Region: Select **US East (N.Virginia)**
* Under **Encryption**, check **Enable Encryption**. Leave the master key as default.(**IMPORTANT**)

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/018.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=fd2c930a0b4ed544456134a5ac1b23e0" alt="" width="1222" height="551" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/018.png" />

5. Click on the **Copy snapshot** button. The snapshot will be created within 3 - 5 minutes.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/019.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=99b894497945caf5a38a988c378b9720" alt="" width="1222" height="450" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/019.png" />

#### Task 5: Restore DB Instance from the encrypted snapshot

1. Click on the encrypted snapshot and click on **Actions**.

2. Click on **Restore snapshot** from the options.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/020.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=e6aedda07f7028f6902a49facc17c3dc" alt="" width="1222" height="415" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/020.png" />

3. Under **Availability and Durability** select Single DB Instance zone

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/021.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=5b5a14a78ef50a610e082d7e7bc07dc9" alt="" width="2862" height="956" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/021.png" />

4. **Settings**, enter the name of DB Instance as **test-db-encrypted**.

5. Make the other settings exactly as the original DB Instance.

6. Under the **DB instance class**, select **Burstable classes (including t classes)** and select **db.t3.micro**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/022.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=244ce1c2d7b3aad3782fc9ded92132bf" alt="" width="1222" height="327" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/022.png" />

7. Under **Encryption**, you can see the **Enable Encryption** is enabled and **cannot make changes since the snapshot is encrypted.**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/023.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=588f546a17f46a61bee70f96274d617d" alt="" width="1222" height="271" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/023.png" />

8. Leave **DB parameter group** and **Option group** as default.

9. Click on **Restore DB Instance** button. The database creation takes around 5-10 minutes.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/024.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=bb2fa9368728ef79c4aebeea924383f2" alt="" width="1222" height="340" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/024.png" />

#### Task 6: Change the name of the original DB Instance

1. We have to make sure that the Endpoint of the restored DB Instance should be the same as the original DB Instance.

2. To do so, we have to change the names of the DB Instances as the names are unique.

3. Select the original DB Instance and click on **Modify**.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/025.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=565853a1aa2d2d7c8e3c8df9c5bafe80" alt="" width="1222" height="205" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/025.png" />

4. Change the DB Instance Identifier to **test-db-unencrypted**.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/026.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=4b56e01553cef63fb16ab8cd26ecb7e4" alt="" width="1222" height="307" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/026.png" />

5. Leave everything as default and click on **Continue**.

6. Verify the new values of the DB Instance Identifier and the Endpoint.

7. Under **Scheduling of modifications**, select **Apply Immediately** and click on **Modify DB Instance** button.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/027.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=a888266bd8beb3a7235f400f36ceb428" alt="" width="1222" height="456" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/027.png" />

8. It might take some time to reboot the DB Instance. Press ctrl+R if you are not able to see the changes.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/028.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=89391f1992f66a0d65fc576857cab1aa" alt="" width="1222" height="312" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/028.png" />

#### Task 7: Change the name of the Restored DB Instance to the original DB Instance name

1. Select on the restored database and click on **Modify**.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/029.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=07d2b27ab64c3feede9e4dc244e95389" alt="" width="1222" height="249" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/029.png" />

2. Change the DB Instance Identifier to **test-db**.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/030.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=12fe797e58507916ba4a8a2b49c4864f" alt="" width="1222" height="298" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/030.png" />

3. Leave everything as default and click on **Continue**.

4. Verify the new values of the DB Instance Identifier and the Endpoint.

5. Under **Scheduling of modifications**, select **Apply Immediately** and click on **Modify DB Instance** button.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/031.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=107d09578d6a6a8e8e9c5a37a0237a44" alt="" width="1222" height="455" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/031.png" />

6. It might take some time to reboot the DB Instance.  Press ctrl+R if you are not able to see the changes.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/032.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=908137e4fe032a1d4a495cf85ef75b39" alt="" width="1222" height="306" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/032.png" />

7. Once the database is modified, click and open **test-db** i.e, the encrypted DB Instance.

8. Click on the database and navigate to the **Configuration** tab. You can notice that the **Encryption** is **enabled**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/033.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=babb6916dc51620e1f374d947179cdc9" alt="" width="943" height="399" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/033.png" />

#### Task 8: Delete the unencrypted RDS DB Instance and snapshot

1. Since we have the encrypted DB Instance, we shall delete the unencrypted DB Instance and the snapshot associated.

2. Click on **Databases** present to the left of the screen.

3. Select the Unencrypted DB Instance (i.e **test-db-unencrypted**) and click on **Actions**.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/034.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=1e23f49ac3c0f3ac8555699dfe5edb6a" alt="" width="1222" height="261" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/034.png" />

4. Click on the **Delete** option.

5. Uncheck the Create final snapshot option.

6. Check the Acknowledge box.

7. Confirm the deletion by entering **delete me** and click on **delete**.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/035.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=e4d29606b4451e66aacc00dea96cc145" alt="" width="1168" height="1170" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/035.png" />

8. Click on the **Snapshots** on the left of your screen.

9. Under **Manual snapshots**, select the unencrypted snapshot (i.e. **test-snapshot-01**) and click on **Actions**.

10. Click on the **Delete snapshot** option.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/036.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=60240c77651e3d8217eb701a0055ae35" alt="" width="1222" height="418" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/036.png" />

11. Confirm by clicking on the **Delete** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/037.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=dec6c6a1de748b7748792439fa6fa676" alt="" width="1168" height="390" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/037.png" />

12. In this way, you can encrypt an unencrypted RDS DB Instance.

13. Wait till both resources are completely deleted. This step is to avoid confusion in the validation report.

> #### Do you know?
>
> Database encryption is a critical component of a comprehensive security strategy. It helps protect data from unauthorized access, complies with regulatory requirements, mitigates the impact of data breaches, enhances cloud security, builds trust with customers, and mitigates insider threats.

1. Once the lab steps are completed, please click on the **Validation** button on the right-side panel.

### Task 9: Delete AWS Resources

##### Deleting the DB Instance

1. Click on **Databases** present to the left of the screen.

2. Select the DB Instance and click on **Actions**.

3. Click on the **Delete** option.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/039.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=b9ca09ec6d296adf1f7e4c7b56e40b5a" alt="" width="1222" height="281" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/039.png" />

4. Uncheck the Create final snapshot option.

5. Check the Acknowledge box.

6. Confirm the deletion by entering **delete me** and click on **delete**.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/040.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=980cf2d7a00afb63ac0aab4288de794e" alt="" width="1168" height="1178" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/040.png" />

7. The status changes to **Deleting** and the DB Instance gets deleted.

8. You can proceed to further steps even if it is in a **deleting** state.

##### Deleting the Snapshot

1. Click on the **Snapshots** on the left of your screen. Under **Manual snapshots**, select the unencrypted snapshot and click on **Actions**.
2. Click on the **Delete Snapshot** option.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/041.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=a110fc203c24304b795a13280b54807a" alt="" width="1222" height="415" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/041.png" />
3. Confirm by clicking on the **Delete** button.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/K03DxSqV4ATZ2nJJ/images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/042.png?fit=max&auto=format&n=K03DxSqV4ATZ2nJJ&q=85&s=e542e277e1c3dae7348fd3821f283b02" alt="" width="1174" height="388" data-path="images/labs/how-to-encrypt-an-unencrypted-rds-db-instance/042.png" />

### Completion and Conclusion

1. You have created an unencrypted Amazon RDS DB Instance.
2. You have taken the snapshot of the DB Instance.
3. You have made a copy of the snapshot and encrypted it.
4. You have restored the DB Instance with the copied snapshot.
5. You have changed the names of the original and restored DB instances.
6. You have made sure that the Endpoint of the restored database is the same as the originally created DB Instance.
7. You have deleted the Unencrypted DB Instance and snapshot.

### End Lab

1. Sign out of AWS Management Console.
2. You have successfully completed the lab.
3. Once you have completed the steps, click on **End Lab** from your IP Lab Portal and wait till the process gets completed.

## What gets checked

When you press **Check my work**, the platform verifies each of these:

* **Launch RDS instance** — Check whether an RDS Instance is created or not
* **Create RDS Snapshot** — Check whether an RDS Snapshot is created or not.

## Related help

* [FAQs and Troubleshooting](/aws-saa/support/faqs-and-troubleshooting)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.