A company operates a large fleet of Linux and Windows Amazon EC2 instances in private subnets. The company requires the most secure possible method for remote administration in AWS. Which solution meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Do not provision SSH-RSA key pairs when launching new instances. Use AWS Systems Manager Session Manager for remote access..
Why this is the answer
The most secure solution is to avoid provisioning SSH-RSA key pairs and use AWS Systems Manager Session Manager. Session Manager provides secure, auditable, and browser-based or CLI-based access to instances without opening inbound ports, managing SSH keys, or using bastion hosts. This eliminates the risk associated with key management and exposure. Generating new SSH-RSA key pairs for existing instances still involves managing keys, which is less secure than not using them at all. While EC2 Instance Connect provides a secure way to connect to instances using SSH, it still relies on SSH keys and requires inbound SSH ports to be open, making it less secure than Session Manager, which operates without open inbound ports.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed