SAA-C03 Design Secure Architectures Practice Question
A company hosts a customer analytics portal on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?
⚠ Common exam trap
Watch out — candidates often default to a bastion host (Option D) as the traditional solution for secure administrative access, but fail to recognize that Session Manager provides the same functionality without any inbound ports, which is the exact requirement stated in the question.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Systems Manager Session Manager with the required instance role
AWS Systems Manager Session Manager allows secure, auditable shell access to EC2 instances without opening inbound SSH (port 22) or RDP (port 3389) ports to the internet. It uses the AWS Systems Manager agent on the instance, which initiates an outbound connection to the AWS Systems Manager service over HTTPS (port 443), and the required IAM instance role grants permissions for this communication. This eliminates the need for a bastion host or public IP addresses, meeting the security requirement of no open inbound ports.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An internet gateway attached to the private subnet
Why it's wrong here
An internet gateway is a horizontally scaled, redundant VPC component that provides a target for a 0.0.0.0/0 route, but it is attached to a VPC, not a subnet. A private subnet by definition has no route to an internet gateway, and even if traffic were routed, an IGW only performs NAT for outbound connections; it provides no authentication, authorization, or session management. Therefore it cannot enable secure administrative access—it simply doesn't address who is allowed to connect or how sessions are controlled.
- ✗
A public Elastic IP address on each instance
Why it's wrong here
A public Elastic IP address merely assigns a fixed public IPv4 address to an instance's network interface. It does not verify caller identity, encrypt traffic, or restrict who can initiate administrative sessions; the instance still requires separate SSH/RDP configuration, security group rules, and credential management. Making instances directly reachable via public IP can actually expand the attack surface and bypass the benefit of placing workloads in a private subnet.
- ✓
AWS Systems Manager Session Manager with the required instance role
Why this is correct
AWS Systems Manager Session Manager establishes an interactive shell connection through the SSM Agent using a bidirectional channel over the AWS API, controlled by the instance's IAM role. Because no security group ingress rule is needed, there is no inbound SSH/RDP exposure, and each session is automatically audited through AWS CloudTrail with optional session logs to S3/CloudWatch Logs. The required IAM role grants least-privilege permissions (e.g., AmazonSSMManagedInstanceCore) and lets administrators restrict actions centrally via IAM policies, providing secure, audited administrative access.
- ✗
A bastion host with SSH open to 0.0.0.0/0
Why it's wrong here
A bastion host is a legitimate jump server pattern, but opening SSH to 0.0.0.0/0 eliminates its security value by allowing any IP address on the internet to attempt authentication against the instance. This exposes the bastion to port scanning, brute-force attacks, and software exploits, and it violates the security-group principle of allowing only specific, known source IPs. To be secure, the security group should be scoped to authorized egress IPs and use strong key-based authentication, session recording, or identity-based access controls.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.