A company runs an application on Amazon EC2 instances that process confidential customer data. The company must restrict access and does not allow opening inbound ports, maintaining bastion hosts, or managing SSH keys. A security engineer needs secure access to the instances and wants to capture, store, and access fully encrypted session logs. Which solution meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Use AWS Systems Manager Session Manager to connect to the EC2 instances. Configure Amazon CloudWatch logging. Enable upload of session logs and allow only encrypted CloudWatch Logs log groups..
Why this is the answer
The correct answer is to use AWS Systems Manager Session Manager because it allows secure, auditable access to EC2 instances without opening inbound ports, managing SSH keys, or using bastion hosts, directly addressing the core requirements. Session Manager can be configured to send session logs to Amazon CloudWatch Logs, and the option to enable upload of session logs and allow only encrypted CloudWatch Logs log groups ensures that the logs are captured, stored, and encrypted as required. AWS Control Tower and AWS Security Hub are incorrect because they are governance and security posture management services, respectively, and do not provide direct access to EC2 instances. The third incorrect option, while using Session Manager, incorrectly states "Configure Amazon CloudWatch monitoring to record sessions" instead of "logging," and "store session logs in selected CloudWatch Logs log groups" does not explicitly mention the encryption requirement for the log groups.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed