passdrill
AWS SAA-C03 · EC2 & Compute · Card 022/024 easy

A security team wants engineers to connect to private EC2 instances that have no public IP address and no inbound rule for SSH or RDP, without managing SSH key pairs or a bastion host, while keeping a centralized, IAM-controlled, logged record of every session. Which approach satisfies all of these requirements?

  1. EC2 Instance Connect, since it also avoids opening inbound SSH ports
  2. AWS Systems Manager Session Manager, using the SSM Agent and an IAM role attached to the instance
  3. A bastion host in a public subnet with a security group restricted to the engineers' office IP range
  4. Enabling IMDSv2 on each instance to allow authenticated shell access over the metadata endpoint
Next card → Shuffle