SAA-C03 Design Secure Architectures Practice Question
A company hosts a e-learning platform on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?
⚠ Common exam trap
Watch out — candidates often assume a bastion host (Option B) is the only secure way to manage instances, but they overlook that Session Manager provides a more secure, agent-based solution that eliminates the need for any open inbound ports or public IP addresses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Systems Manager Session Manager with the required instance role
AWS Systems Manager Session Manager allows secure shell access to EC2 instances without opening inbound ports (SSH/RDP) or using a bastion host. It uses the AWS Systems Manager agent and an IAM instance role to establish a bidirectional connection over HTTPS to the AWS Systems Manager service, eliminating the need for public IP addresses or internet-facing security groups.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A public Elastic IP address on each instance
Why it's wrong here
A public Elastic IP address only provides a static public IP that can be reached over the internet; it does not inherently grant any administrative access, authentication, or authorization to the instance. Even with an EIP, you would still need to open SSH/RDP from a security group, which either exposes management ports broadly or requires additional (often insecure) connectivity options. The EIP also offers no audit trail, IAM-based identity, or session control, making it irrelevant to secure administrative access.
- ✗
A bastion host with SSH open to 0.0.0.0/0
Why it's wrong here
A bastion host is a valid pattern for centralized access, but opening SSH to 0.0.0.0/0 means anyone on the internet can attempt to reach the bastion, subjecting it to brute-force, credential-stuffing, and exploit attacks. This approach dramatically increases the attack surface and defeats the purpose of a jump host because it does not restrict source IPs to trusted networks or operations teams. The correct practice would be to limit SSH source to a controlled CIDR or better, remove inbound SSH entirely by using a service like Session Manager.
- ✗
An internet gateway attached to the private subnet
Why it's wrong here
An internet gateway is a horizontally scaled, redundant VPC component that connects a VPC to the internet, but it is attached to the VPC itself, not directly to a private subnet. A private subnet does not have a route to an internet gateway by definition; adding an internet gateway route would turn it into a public subnet and expose the instances, not provide secure administration. Even if attached, it only enables bidirectional internet traffic and does nothing to provide authenticated, audited shell access to an EC2 instance.
- ✓
AWS Systems Manager Session Manager with the required instance role
Why this is correct
AWS Systems Manager Session Manager provides secure, auditable shell-level access to EC2 instances without requiring inbound SSH/RDP ports. An IAM instance role grants the SSM agent permission to connect outbound to the Systems Manager service, and users authenticate via IAM with the ability to enforce session policies and log sessions to CloudTrail/S3/CloudWatch Logs. This avoids public exposure, enables centralized permissions and auditing, and works for instances in private subnets or without public IPs.
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.