SCS-C02 exam dumps

SCS-C02 practice question 343 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 343

Single answer

Your company has prohibited the use of public-facing bastion hosts for connecting to EC2 instances. Instead, they want a solution that provides secure remote access without requiring these instances to have public IP addresses. You need to ensure that engineers can perform administrative tasks such as running commands and troubleshooting, while maintaining a high level of security and auditing capabilities. Which approach should you implement?

  1. A

    Use AWS Systems Manager Session Manager to establish remote sessions to the EC2 instances.

  2. B

    Enable SSH access with a security group rule allowing inbound traffic from the engineering team's IP address.

  3. C

    Use a VPN connection to the private subnet where the EC2 instances are deployed, and then SSH into the instances.

  4. D

    Deploy a bastion host in a public subnet and restrict access via security group rules.

Show answer and explanation

Correct answer: A

Explanation

AWS Systems Manager Session Manager is the best solution for secure remote access in this scenario. It eliminates the need for public IP addresses, avoids opening inbound SSH ports, and provides native logging and auditing capabilities through AWS CloudTrail and AWS CloudWatch Logs. This aligns with the company's requirements for security and compliance.

  • A. Correct.

    Correct: AWS Systems Manager Session Manager allows you to securely connect to EC2 instances without requiring a public IP address or opening SSH ports. It also provides built-in auditing capabilities via AWS CloudTrail.

  • B. Incorrect.

    Incorrect: Enabling SSH access via security group rules still exposes the EC2 instances to potential risks, even if the IP is restricted. It also requires public IP addresses for the instances, which violates the company's requirement.

  • C. Incorrect.

    Incorrect: While using a VPN can provide secure access, it introduces additional complexity and does not inherently include auditing capabilities like Session Manager does.

  • D. Incorrect.

    Incorrect: Deploying a bastion host violates the company's policy of avoiding public-facing bastion hosts and requires additional effort to secure and manage.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam