SAA-C03 Design Secure Architectures Practice Question
A company hosts a image sharing application on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?
⚠ Common exam trap
Test-takers frequently default to a bastion host (Option D) as a traditional solution, but fail to recognize that a bastion host still requires opening SSH/RDP to the internet (even if only to the bastion), which violates the 'without opening SSH or RDP ports to the internet' constraint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Systems Manager Session Manager with the required instance role
AWS Systems Manager Session Manager allows administrators to establish secure shell (SSH) or PowerShell (RDP) sessions to EC2 instances without opening any inbound ports. It uses the SSM Agent and the AWS Systems Manager service, which initiates outbound connections to the AWS cloud over HTTPS (port 443). The required instance role grants permissions for the agent to communicate with Systems Manager, enabling secure, auditable access without public IP addresses or bastion hosts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Systems Manager Session Manager with the required instance role
Why this is correct
AWS Systems Manager Session Manager gives you encrypted, browser-based shell access to EC2 instances without opening any inbound ports. The instance must have the SSM agent installed and be assigned an IAM instance role with AmazonSSMManagedInstanceCore, allowing it to poll the SSM API over TLS. User access is governed by IAM policies and all shell activity is logged to CloudTrail and optionally S3/CloudWatch Logs, giving audited secure administration.
- ✗
An internet gateway attached to the private subnet
Why it's wrong here
An internet gateway is a VPC-level routing component that enables communication between a VPC and the internet; it attaches to a VPC, not to a subnet, and a private subnet lacks a route to it. Even if you added a 0.0.0.0/0 route to the internet gateway, the instance would simply be directly internet-reachable — that does not create a secure administrative session or strip away unencrypted RDP/SSH vulnerabilities. Without an identity-based, audited access mechanism, an internet gateway alone is just network plumbing, not a secure administration solution.
- ✗
A public Elastic IP address on each instance
Why it's wrong here
A public Elastic IP address merely gives the instance a fixed public IPv4 address and direct internet exposure. It does nothing to authenticate users, restrict access, patch vulnerabilities, or encrypt a legacy RDP/SSH session; reaching the instance still depends on open security group rules and valid credentials, which are prime targets for brute-force and credential-stuffing attacks. A public IP actually widens the attack surface because any internet host can attempt to connect.
- ✗
A bastion host with SSH open to 0.0.0.0/0
Why it's wrong here
A bastion host is a valid pattern, but only when the SSH source is restricted to a known CIDR — opening it to 0.0.0.0/0 means anyone on the internet can attempt to authenticate and launch brute-force attacks against it. The bastion becomes the single most exposed asset, requiring aggressive patching, monitoring, and key management, and a compromise there would give access to the private instances. This configuration is insecure by design, because it relies on network reachability rather than an AWS-level identity policy.
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.