People asking about "encryption at rest" are really asking if backups of your web application data are encrypted.
Earlier I think it was quite a plague when just un-encrypted backup files were leaking out because someone exposed them on some open FTP to "quick and dirty" copy backups to new environment or to some test environment - and forgot to close it down or remove the files.
Other threat would be developers exposing database server directly to the internet because someone from marketing wants to connect "new shiny super business intelligence" and developers not knowing better than "allow all" on firewall, then someone might steal raw db files but might not really have access to web application and encryption keys.
For the reasons mentioned by author I can see how it seems like security theater. But I think my reasons are quite valid and on topic.