A SysOps administrator must limit Systems Manager Session Manager access to specific groups of EC2 instances. The instances are already labeled with the required tags. What additional tasks must the administrator perform to enforce access controls? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Attach appropriate IAM policies to the users or groups that need Session Manager access., Create an IAM policy that uses a Condition to allow access only to EC2 instances that have the specified tag..
Why this is the answer
To enforce access controls for Session Manager, the administrator must first attach appropriate IAM policies to the users or groups requiring access. These policies define the permissions for Session Manager. Then, to limit access to specific EC2 instances based on tags, the administrator needs to create an IAM policy that includes a Condition element. This condition will specify that Session Manager actions are only allowed when the target EC2 instance has the required tag. This combination of user/group policies and a conditional policy on instance tags ensures granular control. Attaching an IAM role directly to control which users can access instances is incorrect because IAM roles are typically assumed by services or EC2 instances, not directly by users for this purpose. Creating a placement group is unrelated to Session Manager access control. Creating a service account and installing it on instances is not how Session Manager access is managed; Session Manager uses the SSM Agent and IAM for authentication and authorization.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed