Question 1 · choose 1
Administrators need shell access to private EC2 instances. Security requires that no inbound ports are open on the instances, that no SSH keys are managed, that access is granted through IAM, and that every session's commands and output are stored in an S3 bucket encrypted with a KMS key. Which solution meets these requirements?
- AEC2 Instance Connect Endpoint with temporary SSH keys pushed for each connection
- BA bastion host in a public subnet with SSH keys stored in Secrets Manager
- CSession Manager with session logging to an S3 bucket encrypted with the key
- DSystems Manager Run Command with command output written to the encrypted bucket
Show the answer and why
AEC2 Instance Connect Endpoint with temporary SSH keys pushed for each connection
Incorrect
The instance security group must allow inbound SSH from the endpoint, and the service does not record session output to S3.
BA bastion host in a public subnet with SSH keys stored in Secrets Manager
Incorrect
A bastion needs an open SSH port and keys to manage, which the requirements rule out.
CSession Manager with session logging to an S3 bucket encrypted with the key
Correct
Session Manager needs no inbound ports, bastions or SSH keys, is controlled with IAM policies, and can log session data to S3 with KMS encryption.
DSystems Manager Run Command with command output written to the encrypted bucket
Incorrect
Run Command sends commands without opening ports, but it does not provide interactive shell sessions for administrators.
"No open ports, no keys, IAM-controlled, sessions recorded" is the definition of Session Manager with session logging.
AWS documentation