Which solution will meet this requirement?
A team of On-call engineers frequently needs to connect to Amazon EC2 Instances In a private subnet to troubleshoot and run commands. The Instances use either the latest AWS-provided Windows Amazon Machine Images (AMIs) or Amazon Linux AMIs.
The team has an existing IAM role for authorization. A SysOps administrator must provide the team with access to the Instances by granting IAM permissions to this
Which solution will meet this requirement?
A . Add a statement to the IAM role policy to allow the ssm:StartSession action on the instances. Instruct the team to use AWS Systems Manager Session Manager to connect to the Instances by using the assumed IAM role.
B . Associate an Elastic IP address and a security group with each instance. Add the engineers’ IP addresses to the security group inbound rules. Add a statement to the IAM role policy to allow the ec2:AuthoflzeSecurityGroupIngress action so that the team can connect to the Instances.
C . Create a bastion host with an EC2 Instance, and associate the bastion host with the VPC. Add a statement to the IAM role policy to allow the ec2:CreateVpnConnection action on the bastion host. Instruct the team to use the bastion host endpoint to connect to the instances.
D Create an internet-facing Network Load Balancer. Use two listeners. Forward port 22 to a target group of Linux instances. Forward port 3389 to a target group of Windows Instances. Add a statement to the IAM role policy to allow the ec2:CreateRoute action so that the team can connect to the Instances.
Answer: A
Explanation:
Step-by-Step
Understand the Problem:
Engineers need to connect to EC2 instances in a private subnet for troubleshooting. The instances are using Windows or Amazon Linux AMIs. The team already has an IAM role for authorization. Analyze the Requirements:
Provide secure and efficient access to the instances without exposing them directly to the internet.
Utilize existing IAM role for access control.
Evaluate the Options:
Option A: Use AWS Systems Manager Session Manager.
Allows secure and auditable SSH or RDP access to EC2 instances without the need for bastion hosts or opening inbound ports.
Add a policy to allow the ssm:StartSession action.
Option B: Use Elastic IP and security group.
Exposes instances to direct access, increasing security risks.
Option C: Use a bastion host.
Requires additional infrastructure and maintenance.
Option D: Use an internet-facing Network Load Balancer.
Exposes instances to direct access via load balancer, not ideal for private subnets.
Select the Best Solution:
Option A: Using AWS Systems Manager Session Manager is the most secure and efficient solution. It eliminates the need for additional infrastructure and avoids exposing instances to the internet.
Reference: AWS Systems Manager Session Manager
Controlling Access to Session Manager
AWS Systems Manager Session Manager provides secure and auditable access to EC2 instances in a private subnet using IAM roles.
Latest SOA-C02 Dumps Valid Version with 54 Q&As
Latest And Valid Q&A | Instant Download | Once Fail, Full Refund