SAA-C03 Design Secure Architectures Practice Question
A company hosts a financial reporting platform on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?
⚠ Common exam trap
Test-takers frequently default to a bastion host (Option B) as the traditional solution, but the question explicitly prohibits opening SSH or RDP ports to the internet, and a bastion host still requires those ports open (even if restricted to a CIDR), which fails the requirement; Session Manager avoids any inbound port exposure entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Systems Manager Session Manager with the required instance role
AWS Systems Manager Session Manager allows secure shell access to EC2 instances without opening inbound ports (SSH 22 or RDP 3389) to the internet. It uses the AWS Systems Manager agent on the instance, combined with an IAM instance role that grants permissions to communicate with the Systems Manager API, establishing a bidirectional tunnel over HTTPS (port 443). This satisfies the requirement of no public-facing SSH or RDP ports while enabling administrative connectivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A public Elastic IP address on each instance
Why it's wrong here
A public Elastic IP merely maps a persistent public IP to an instance; it does not provide any authentication, authorization, or audit capability. Even if paired with SSH, it exposes the management interface directly to the internet, greatly increasing attack surface and violating the principle of least exposure. It does not meet the requirement for audited, secure administrative access.
- ✗
A bastion host with SSH open to 0.0.0.0/0
Why it's wrong here
A bastion host is a legitimate jump box, but opening SSH to 0.0.0.0/0 exposes it to the entire internet, enabling brute-force attacks and unauthorized access attempts. The security group should restrict inbound SSH to known administrative CIDRs or, preferably, front it with a more secure access method. As written, this configuration increases the attack surface rather than providing controlled, audited access.
- ✓
AWS Systems Manager Session Manager with the required instance role
Why this is correct
AWS Systems Manager Session Manager uses the SSM agent and an IAM instance role to provide secure shell access without needing inbound ports such as 22 or 3389. It authenticates through the AWS control plane, encrypts all session traffic, and can record sessions in CloudTrail and S3 for auditing. This provides the required audited, secure administrative access while keeping instances in a private subnet.
- ✗
An internet gateway attached to the private subnet
Why it's wrong here
An internet gateway is a network component that enables traffic between a VPC and the internet, not a service for administrative access. A private subnet is defined by having no route to an internet gateway, so attaching one would expose instances to inbound traffic without adding any authentication or audit trail. This approach completely fails to address secure administration and would actually weaken the security posture.
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.