AWS Certified SysOps Administrator – AssociateNetworking and Content DeliveryEasy
A SysOps administrator needs to securely access EC2 instances in a private subnet without exposing them to the internet and without using a bastion host or VPN. The instances need to receive commands and software updates from AWS Systems Manager. Which solution should the administrator implement?
- AConfigure a NAT Gateway in the private subnet.
- BSet up a VPC Endpoint for AWS Systems Manager in the VPC.
- CCreate a new Internet Gateway and route traffic through it.
- DAttach an Elastic IP address to each EC2 instance.
Show answer & explanationAnswer & explanation
Correct answer: B. Set up a VPC Endpoint for AWS Systems Manager in the VPC.
VPC Endpoints allow private connections from your VPC to supported AWS services and VPC endpoint services powered by AWS PrivateLink. This enables EC2 instances in private subnets to securely communicate with services like AWS Systems Manager without traversing the internet or requiring a NAT Gateway.
Why the other options are wrong
- A. A NAT Gateway allows outbound internet access but doesn't facilitate inbound AWS service communication privately.
- C. An Internet Gateway exposes the VPC to the internet, which is against the security requirement.
- D. Elastic IP addresses expose instances to the internet, which violates the requirement of not exposing them.
VPC Endpoint for Systems Manager
A VPC Endpoint allows EC2 instances in private subnets to securely communicate with AWS Systems Manager without requiring an internet gateway, NAT device, or public IP addresses.
- Enables private connectivity to AWS services.
- Bypasses the public internet for enhanced security.
- Supports Systems Manager for instance management.
Memory trick: Private instances need a 'private door' to AWS services, not an 'open window'.