A security auditor is reviewing an AWS environment and discovers several Amazon EC2 instances that are directly exposed to the public internet via public IP addresses and have SSH (port 22) open to 0.0.0.0/0. The auditor recommends immediate action to secure these instances. Which is the MOST secure and operationally efficient way to allow administrators to securely connect to these EC2 instances?
- ATerminate the EC2 instances with public IPs and relaunch them into private subnets. Configure a Bastion host in a public subnet with restricted SSH access, and allow administrators to connect to the private instances via the Bastion host.
- BReplace the public IP addresses with Elastic IPs and configure Network ACLs to allow SSH only from a specific jump box EC2 instance within the same VPC.
- CDisable SSH access entirely on the security groups. Implement AWS Systems Manager Session Manager for remote administration, allowing access through an IAM policy without opening any inbound ports.
- DModify the security groups to restrict SSH access to a specific range of trusted corporate IP addresses. Instruct administrators to connect using their corporate VPN.
Show answer & explanationAnswer & explanation
Correct answer: C. Disable SSH access entirely on the security groups. Implement AWS Systems Manager Session Manager for remote administration, allowing access through an IAM policy without opening any inbound ports.
AWS Systems Manager Session Manager provides a highly secure and auditable way to access EC2 instances without opening any inbound ports (like SSH 22) to the internet or even within a VPC. It leverages IAM for authorization and integrates with CloudTrail for logging, making it the most secure and operationally efficient solution.
Why the other options are wrong
- A. This is a valid and secure approach (bastion host), but Session Manager is generally more operationally efficient as it requires less infrastructure to manage and no SSH keys.
- B. Using Elastic IPs doesn't change the security posture regarding open ports. NACLs can filter, but a jump box still requires SSH to be open to it, and Session Manager is a superior solution for direct access without open ports.
- D. Restricting by IP is better than 0.0.0.0/0, but still exposes port 22 to the internet and relies on VPN, which can be bypassed or misconfigured.
AWS Systems Manager Session Manager
A fully managed AWS service that provides secure, auditable, and browser-based or CLI-based remote management of EC2 instances and other supported resources without the need to open inbound ports, manage bastion hosts, or handle SSH keys.
- No open inbound ports (e.g., SSH, RDP) required on instances.
- Uses IAM for granular access control and authorization.
- Sessions are logged to CloudWatch Logs or S3 for auditing.
- Works with instances in private subnets without a public IP.
Memory trick: For EC2 access, 'Session Manager' is like a 'secret tunnel' with no visible doors.