Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A company hosts a B2B file exchange site on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?

⚠ Common exam trap

Watch out — candidates often default to a bastion host (Option A) as the traditional solution, overlooking that AWS Systems Manager Session Manager provides a more secure, port-free alternative that fully meets the 'no open ports' requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Systems Manager Session Manager with the required instance role

AWS Systems Manager Session Manager allows secure shell access to EC2 instances without opening inbound ports (SSH 22 or RDP 3389) to the internet. It uses the AWS Systems Manager agent and an IAM instance role to establish a bidirectional connection via the AWS cloud, eliminating the need for a bastion host or public IP. This meets the requirement for administrators to connect without exposing any network ports.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A bastion host with SSH open to 0.0.0.0/0

    Why it's wrong here

    A bastion host with SSH open to 0.0.0.0/0 is flawed because it allows any source IP on the internet to attempt connections to the management endpoint. While key-based authentication is required, the broad exposure dramatically increases the risk of brute-forcing, protocol-level attacks, and zero-day exploits. A production design should restrict SSH to trusted IP ranges via security groups or replace direct SSH with a managed service like Session Manager.

  • ✓

    AWS Systems Manager Session Manager with the required instance role

    Why this is correct

    AWS Systems Manager Session Manager is correct because it provides secure, audited shell access to the instances without requiring any inbound SSH/RDP ports or an internet-facing management interface. The EC2 instance must have the SSM Agent installed and an IAM instance role with AmazonSSMManagedInstanceCore, and a VPC endpoint or standard internet route for the agent to communicate with the AWS control plane. Each session is logged to AWS CloudTrail and can be streamed to S3 or CloudWatch, giving administrators full auditability.

  • ✗

    A public Elastic IP address on each instance

    Why it's wrong here

    Assigning a public Elastic IP address to each instance is wrong because it exposes the compute resources directly to the internet, but does nothing to control or authenticate administrative access. It simply gives the instance a reachable address, which actually increases the attack surface and requires additional security group and key management. Public EIPs do not provide session auditing, identity-based authorization, or the managed access benefits expected of an administrative solution.

  • ✗

    An internet gateway attached to the private subnet

    Why it's wrong here

    Attaching an internet gateway to the private subnet is incorrect because an internet gateway merely enables two-way communication with the internet for resources that have public IPs; it does not create a secure administrative path. Doing so would defeat the purpose of a private subnet, since instances could become publicly reachable, and it offers no identity control or auditing. Secure administration should use VPC endpoints to AWS Systems Manager or a managed VPN/Direct Connect, not an IGW that simply opens the subnet.

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.