AWS SAA-C03 #37

A company recently launched a variety of new workloads on Amazon EC2 instances in its AWS account. The company needs to create a strategy to access and administer the instances remotely and securely. The company needs to implement a repeatable process that works with native AWS services and follows the AWS Well-Architected Framework.

Which solution will meet these requirements with the LEAST operational overhead?

A. Use the EC2 serial console to directly access the terminal interface of each instance for administration.

B. Attach the appropriate IAM role to each existing instance and new instance. Use AWS Systems Manager Session Manager to establish a remote SSH session.

C. Create an administrative SSH key pair. Load the public key into each EC2 instance. Deploy a bastion host in a public subnet to provide a tunnel for administration of each instance.

D. Establish an AWS Site-to-Site VPN connection. Instruct administrators to use their local on-premises machines to connect directly to the instances by using SSH keys across the VPN tunnel.


B. Attach the appropriate IAM role to each existing instance and new instance. Use AWS Systems Manager Session Manager to establish a remote SSH session.

Option B provides a secure and low-operational-overhead solution that aligns with the AWS Well-Architected Framework:

  1. IAM Roles: By attaching the appropriate IAM roles to the instances, you can control access to AWS services and resources. This ensures that only authorized users or systems can interact with the instances.

  2. AWS Systems Manager Session Manager: This service allows you to establish secure, controlled sessions with instances. It doesn't require opening inbound ports in security groups or network access control lists, which improves security.

  3. Least Operational Overhead: Using Systems Manager Session Manager means you don't have to manage additional infrastructure like bastion hosts or VPN connections. It's a managed service provided by AWS, reducing operational overhead.

  4. Secure: The use of IAM roles and Systems Manager for remote access is in line with security best practices, and it provides a controlled and secure method for administrators to access the instances.

Option A (using the EC2 serial console) might be useful in certain scenarios, but it's not suitable for remote administration on a regular basis due to limitations in functionality.

Option C (using a bastion host) adds additional infrastructure that needs to be managed and secured, which increases operational overhead.

Option D (AWS Site-to-Site VPN) is a valid option for connecting on-premises resources to AWS, but it introduces more complexity and overhead than necessary for this scenario, making it less suitable for the requirement of least operational overhead.

相关推荐
逐流人4 小时前
Ceph分布式存储集群配置与池管理:从配置优先级到PG、复本池与纠删码池
运维·分布式·ceph·云原生·云计算·rados
jqpwxt12 小时前
启点创新科技景区私有化票务管理系统:智慧景区数字化建设核心服务商,以本地部署筑牢景区数字化安全与稳定底座
大数据·人工智能·科技·云计算·旅游
ZhangJun9513 小时前
三次握手、四次挥手的具体细节和流程详解,附加思考题
tcp/ip·计算机网络·云计算
腾讯云大数据15 小时前
腾讯云数据智能体TCDataAgent升级:大数据平台不只“给人用”,也要“给Agent用”
大数据·云计算·腾讯云
河北小博博2 天前
阿里云 ChatOps Agent 让非标准化环境可修复:内核漏洞换盘后的容器恢复
阿里云·云计算
会议咨询2 天前
2026年数据科学、云计算与智能技术国际会议(DCIT 2026)
云计算·数据科学·智能技术
ha_lydms2 天前
MaxCompute中窗口函数
大数据·hadoop·阿里云·云计算·dataworks·maxcompute·odps
GPU实战笔记2 天前
云端 GPU 暂停任务:如何把短期关机与七天资源释放边界分开判断?
云计算·云服务器·数据盘·gpu云计算·实例生命周期
QYR-分析3 天前
刚需赛道:全球一次性有创压力传感器市场深度解析
云计算
AKAMAI3 天前
随着瓦尔·基尔默的AI分身诞生,生成式AI是否正在将好莱坞推向边缘?
人工智能·云原生·云计算