Courseiva

SAA-C03 Design Secure Architectures Practice Question

A startup runs a public web application on Amazon EC2 instances behind an Application Load Balancer. The instances are in a public subnet and currently allow SSH from 0.0.0.0/0 so that engineers can troubleshoot. Auditors flagged this exposure. Engineers still need occasional shell access to the instances, and the company wants the access to be auditable per engineer without managing bastion hosts or distributing key pairs. Which solution best meets these requirements?

⚠ Common exam trap

The trap here is assuming Session Manager requires an open SSH port or a bastion host to function, when the agent only needs outbound connectivity to Systems Manager endpoints.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Move the instances to private subnets, remove the inbound SSH rule, and grant engineers access through AWS Systems Manager Session Manager with IAM policies and session logging to Amazon S3 and CloudWatch Logs.

Session Manager removes the need for inbound SSH, bastion hosts, and key pairs by having the Systems Manager agent establish outbound connections to the service. IAM policies determine which engineers can start sessions on which instances, giving per-person attribution, and session logging to Amazon S3 and CloudWatch Logs satisfies the audit requirement without exposing any listening port.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Keep the instances in the public subnet, restrict SSH to the corporate office CIDR, and distribute a shared PEM key pair to all engineers through AWS Secrets Manager.

    Why it's wrong here

    Restricting the CIDR reduces exposure but still leaves an open inbound SSH port reachable from the internet if the office range is spoofed or the network is compromised, which does not satisfy the auditors. A shared key pair also destroys per-engineer attribution, since every session appears under the same credential and no one can be individually identified or revoked.

  • ✓

    Move the instances to private subnets, remove the inbound SSH rule, and grant engineers access through AWS Systems Manager Session Manager with IAM policies and session logging to Amazon S3 and CloudWatch Logs.

    Why this is correct

    Session Manager connects to instances through the Systems Manager agent without inbound ports or a bastion host, so the SSH rule can be deleted entirely. Access is governed by IAM, so each engineer's session is attributable, and session logging to Amazon S3 and CloudWatch Logs produces the audit trail the auditors requested without distributing or rotating SSH key pairs.

  • ✗

    Attach an EC2 instance profile granting AmazonSSMManagedInstanceCore to the instances and open port 22 only to the VPC CIDR so Session Manager can reach the instances.

    Why it's wrong here

    Session Manager does not require inbound port 22 at all, because the Systems Manager agent initiates outbound connections to the service endpoints, so this rule is unnecessary exposure. The instance profile is indeed needed, but pairing it with an open SSH port indicates a misunderstanding of how the agent connects and leaves a needless inbound path.

  • ✗

    Deploy a bastion host in a public subnet with a security group that allows SSH only from the corporate CIDR, and have engineers forward through it to reach the instances.

    Why it's wrong here

    A bastion host adds a server to patch, monitor, and pay for, and it still relies on SSH key distribution to each engineer, which conflicts with the requirement to avoid managing key pairs. The bastion itself becomes an internet-facing target, and its logs show connections to the bastion rather than the commands executed on the destination instances.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.