Courseiva
Network Security, Compliance and GovernancemediumMultiple ChoiceObjective-mapped

ANS-C01 Network Security, Compliance and Governance Practice Question

A company wants to allow an external auditor to access a specific EC2 instance in their VPC for a limited time. The auditor will connect via SSH from a known IP address. What is the MOST secure way to grant access?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a bastion host in a public subnet with a security group allowing SSH from the auditor's IP, and allow SSH from the bastion to the instance.

The most secure approach is to use a bastion host (jump box) in a public subnet. The bastion host's security group restricts SSH access to only the auditor's known IP address. The target EC2 instance's security group allows SSH only from the bastion host's private IP, minimizing direct exposure. Option A (assigning a public IP to the instance) exposes the instance directly to the internet, even with a restricted security group, increasing attack surface. Option B (allowing SSH from the entire VPC CIDR) is insecure because any compromised resource within the VPC could access the instance. Option D (client VPN) is secure but adds complexity and cost for a temporary single-instance access; the bastion host is simpler and more direct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Assign a public IP to the instance and create a security group rule allowing SSH from the auditor's IP.

    Why it's wrong here

    Assigning a public IP to the instance and creating a security group rule allowing SSH from the auditor's IP is somewhat secure but still exposes the instance directly to the internet, increasing attack surface compared to a bastion host that can be hardened and monitored separately.

  • Configure a security group for the instance that allows SSH from the VPC CIDR.

    Why it's wrong here

    Configuring a security group that allows SSH from the VPC CIDR is insecure because any compromised resource within the VPC could access the instance, violating the principle of least privilege.

  • Create a bastion host in a public subnet with a security group allowing SSH from the auditor's IP, and allow SSH from the bastion to the instance.

    Why this is correct

    Creating a bastion host in a public subnet with a security group allowing SSH from the auditor's IP, and allowing SSH from the bastion to the instance, is the most secure option. It provides a controlled, auditable entry point and minimizes the attack surface of the target instance.

  • Set up a client VPN endpoint and allow the auditor to connect to the VPC, then SSH to the instance.

    Why it's wrong here

    A client VPN endpoint introduces unnecessary complexity and latency by routing the auditor through a full VPN tunnel, when the requirement is direct SSH from a single known IP address. This approach is tempting because client VPNs are designed for granting broad, secure network-level access to an entire VPC, which would be the correct choice if the auditor needed to reach multiple resources or had a dynamic IP address.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This ANS-C01 question is part of Courseiva's 1,621-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on ANS-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company wants to allow a specific IP address range to access an EC2 instance in a private subnet using a bastion host. The bastion host is in a public subnet. Which security group configuration is correct?

easy
  • A.Bastion security group: inbound SSH from the private instance security group. Private instance security group: inbound SSH from the bastion security group.
  • B.Bastion security group: inbound SSH from the private instance security group. Private instance security group: inbound SSH from the IP range.
  • C.Bastion security group: inbound SSH from the IP range. Private instance security group: inbound SSH from the IP range.
  • D.Bastion security group: inbound SSH from the IP range. Private instance security group: inbound SSH from the bastion security group.

Why D: The bastion host, located in the public subnet, should allow inbound SSH from the specified IP address range (e.g., corporate network) because users initiate the connection from that range to the bastion. The private instance should only allow inbound SSH from the bastion host's security group, not directly from the IP range, to ensure that all access is mediated through the bastion. Option A is incorrect because the bastion should not allow SSH from the private instance; it's the other way around. Option B is incorrect because the bastion should allow SSH from the IP range, not from the private instance. Option C is incorrect because the private instance should not allow SSH directly from the IP range, as it violates the principle of using a bastion.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.