A company has a large fleet of Amazon Linux 2 Amazon EC2 instances that run an application processing sensitive dat
a. Compliance requirements include no exposed management ports, full session logging, and authentication through AWS IAM Identity Center. DevOps engineers occasionally need access for troubleshooting.
Which solution will provide remote access while meeting these requirements?
AWS Systems Manager Session Manager provides secure, auditable shell access to EC2 instances without opening inbound ports. According to AWS Certified Security -- Specialty guidance, Session Manager records all session activity to CloudWatch Logs or Amazon S3 and integrates with IAM Identity Center for centralized authentication.
This solution meets all requirements: no exposed ports, full audit logging, and identity-based access control. EC2 Instance Connect and serial console access do not integrate with Identity Center and may expose management paths.
Referenced AWS Specialty Documents:
AWS Certified Security -- Specialty Official Study Guide
AWS Systems Manager Session Manager
AWS IAM Identity Center Integration
Zack
1 month agoXenia
1 month agoFrancesco
1 month agoDoretha
2 months agoHortencia
2 months agoKris
2 months agoSueann
2 months agoEun
2 months agoBrent
3 months agoKimi
3 months agoOlive
3 months agoIn
3 months agoPhyliss
4 months agoKasandra
4 months agoGianna
4 months agoColeen
4 months agoPaz
4 months agoEna
5 months agoLoreta
5 months ago