AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium
A systems administrator wants to allow team members to remotely access EC2 instances for troubleshooting without opening inbound SSH port 22 in the security group or managing SSH key pairs. Which AWS capability should be used?
- AAWS Certificate Manager private CA
- BAmazon Cognito federated identities
- CAWS Systems Manager Session Manager
- DAWS Direct Connect
Show answer & explanationAnswer & explanation
Correct answer: C. AWS Systems Manager Session Manager
Systems Manager Session Manager provides secure, auditable shell access to EC2 instances through the Systems Manager agent without requiring open inbound ports, SSH keys, or bastion hosts, improving security posture.
Why the other options are wrong
- A. ACM Private CA issues certificates, not remote access to instances
- B. Cognito manages application user identities, not EC2 shell access
- D. Direct Connect is a dedicated network connection to AWS, unrelated to instance access
Systems Manager Session Manager
A Systems Manager capability that provides secure, browser-based or CLI shell access to managed instances without opening inbound ports or managing SSH keys.
- No need to open port 22 or manage bastion hosts
- Requires the SSM Agent and an IAM role attached to the instance
- All session activity can be logged for auditing via CloudTrail/S3
Memory trick: Session Manager opens a hidden tunnel, no keys, no open doors needed.