Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A team wants to remove a bastion host used for administrative access to EC2 instances in private subnets. The instances should be reachable only for occasional troubleshooting by engineers who authenticate with AWS SSO. What is the best secure alternative within AWS, assuming the instances already have an instance profile attached?

⚠ Common exam trap

A common mix-up: candidates think a bastion host is the only way to access private instances, overlooking that AWS Systems Manager Session Manager provides a fully managed, agent-based alternative that eliminates the need for any bastion host or open inbound ports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Systems Manager Session Manager, enabling the required SSM permissions in the instance profile and restricting access to engineers via IAM.

AWS Systems Manager Session Manager provides secure, auditable, agent-based access to EC2 instances without requiring a bastion host, public IPs, or open inbound ports. Since the instances already have an instance profile, you only need to add the required SSM permissions (e.g., AmazonSSMManagedInstanceCore) to that profile and use IAM policies to restrict Session Manager access to engineers authenticated via AWS SSO. This eliminates the bastion host while maintaining secure, on-demand troubleshooting access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use AWS Systems Manager Session Manager, enabling the required SSM permissions in the instance profile and restricting access to engineers via IAM.

    Why this is correct

    Session Manager avoids inbound SSH from the internet by initiating interactive sessions through Systems Manager. The instance profile must allow SSM actions like StartSession, and engineers’ IAM permissions restrict who can connect. This is a commonly recommended bastion-free alternative that improves security and reduces exposed network paths.

  • ✗

    Keep the bastion host but move it into a private subnet; engineers can connect by using a corporate VPN into the VPC.

    Why it's wrong here

    A bastion host remains a high-value target and still requires controlled network access. Even if the bastion is private, inbound connectivity and SSH exposure remain. Session Manager provides a more direct elimination of the bastion as well as auditability.

  • ✗

    Attach a public IP to each private instance so engineers can SSH directly and use security groups to restrict access.

    Why it's wrong here

    Attaching public IPs to instances in a private subnet defeats the isolation that the subnet was designed to provide, exposing every instance to direct SSH attempts from the internet. Security groups are useful for limiting access, but they are network-layer controls and do not substitute for identity-based authorization or session auditing; a single misconfigured rule or compromised instance broadens the attack surface. This approach still leaves management ports like 22 open to the network, whereas Session Manager brokers connections through the AWS control plane without any inbound port.

  • ✗

    Create a security group rule that allows engineers’ source IP addresses to reach instances over RDP on port 3389.

    Why it's wrong here

    Opening port 3389 to engineer IPs assumes a Windows-focused administrative path and requires a direct network route to each instance, which keeps the management plane exposed to the internet and vulnerable to brute-force RDP attacks if the source IP is spoofed or a rule is too broad. IP-based allowlisting is also brittle because engineer addresses change and it cannot enforce per-user IAM permissions or produce an auditable record of who did what. This option neither removes a bastion nor addresses the core requirement; it merely shifts the exposure from a single jump host to the target instances themselves, and it is irrelevant for Linux workloads.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.