AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityHard

A security auditor is reviewing an AWS environment and discovers several Amazon EC2 instances in public subnets that are running critical backend services. These instances have Security Groups that allow inbound SSH (port 22) from 0.0.0.0/0. The auditor recommends immediate action to mitigate this high-risk vulnerability. Which is the MOST secure and efficient way to restrict SSH access while maintaining operational functionality?

  1. AMove the EC2 instances to private subnets and configure a Bastion Host in a public subnet for SSH access.
  2. BDisable SSH access entirely on the EC2 instances and rely on AWS Systems Manager Session Manager for remote administration.
  3. CModify the Security Group to restrict inbound SSH to a specific CIDR range of trusted IP addresses only.
  4. DImplement a Network ACL to deny inbound SSH on port 22 for the public subnets.
Show answer & explanation

Correct answer: B. Disable SSH access entirely on the EC2 instances and rely on AWS Systems Manager Session Manager for remote administration.

Disabling SSH and using AWS Systems Manager Session Manager is the most secure approach. Session Manager provides secure, auditable, and browser-based shell access to EC2 instances without opening inbound ports, managing SSH keys, or requiring a bastion host. This eliminates the need for port 22 to be open at all.

Why the other options are wrong

  • A. Moving to private subnets with a Bastion Host is a good practice, but it's less efficient and secure than Session Manager because it still involves managing a separate instance (the Bastion Host) and its associated security (e.g., patching, SSH keys).
  • C. While restricting to specific CIDR ranges improves security, it still exposes port 22 and requires managing those IP ranges, which can be dynamic or complex in larger organizations.
  • D. Implementing a Network ACL to deny SSH would prevent legitimate access, making it impossible to administer the instances via SSH, thus breaking operational functionality. ACLs are stateless and would block all traffic on port 22.

Secure EC2 Remote Access

Utilizing AWS Systems Manager Session Manager for secure, port-less, and auditable remote administration of EC2 instances, eliminating the need for open SSH/RDP ports.

  • No open inbound ports (e.g., 22, 3389).
  • Browser-based or CLI access.
  • Integrated with IAM for permissions.
  • Auditable through CloudTrail.

Memory trick: Session Manager: No SSH, No Problem!

More Domain 3: Infrastructure Security questions