AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityMedium

A security auditor is reviewing an AWS environment and discovers several Amazon EC2 instances running critical applications that require remote administration. The current practice involves using SSH with key pairs, but the organization wants to implement a solution that eliminates the need to open inbound SSH ports on security groups, centrally manages access, and records all administrative sessions for auditing purposes. Which AWS service can accomplish these requirements effectively?

  1. AAWS Systems Manager Session Manager
  2. BAWS Certificate Manager (ACM)
  3. CAWS CloudShell
  4. DAWS CloudTrail
Show answer & explanation

Correct answer: A. AWS Systems Manager Session Manager

AWS Systems Manager Session Manager provides secure and auditable remote access to EC2 instances without opening inbound SSH ports. It uses IAM for access control and integrates with S3/CloudWatch Logs for session recording, directly addressing all the stated requirements.

Why the other options are wrong

  • B. AWS Certificate Manager is for managing SSL/TLS certificates and does not provide remote access capabilities.
  • C. AWS CloudShell provides a browser-based shell in the AWS Management Console, but it's not for remote administration of EC2 instances in the way Session Manager is.
  • D. AWS CloudTrail records API calls and events but does not provide remote access to instances; it's an auditing service.

Secure EC2 Remote Access

AWS Systems Manager Session Manager provides a secure, auditable, and port-free way to remotely access and manage EC2 instances.

  • No open inbound ports (SSH/RDP) needed.
  • Uses IAM for granular access control.
  • Records sessions for auditing (S3/CloudWatch Logs).
  • Works with Windows and Linux instances.

Memory trick: Session Manager Secures SSH Sessions.

More Domain 3: Infrastructure Security questions