Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company is using AWS Systems Manager Session Manager to provide secure shell access to EC2 instances without opening inbound ports. Which of the following is a requirement for this setup?

⚠ Common exam trap

A common mix-up: candidates assume Session Manager requires inbound network access (like SSH) or public IPs, but the key requirement is the IAM role that grants the SSM agent permission to communicate with the AWS Systems Manager service via outbound-only HTTPS connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The EC2 instance must have an IAM role that allows SSM actions.

AWS Systems Manager Session Manager establishes a secure shell connection to EC2 instances without requiring inbound ports. The EC2 instance must have an IAM role attached that includes the AWS managed policy AmazonSSMManagedInstanceCore, which grants permissions for the SSM agent to communicate with the Systems Manager service. This IAM role is essential because the SSM agent uses AWS credentials from the instance metadata to authenticate and establish a bidirectional control channel via HTTPS (port 443) to the Systems Manager endpoint, not through traditional SSH.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The EC2 instance must have an IAM role that allows SSM actions.

    Why this is correct

    The SSM Agent on the EC2 instance requires an IAM instance role that grants the necessary Systems Manager permissions, such as the managed policy AmazonSSMManagedInstanceCore. This role provides temporary credentials that the agent uses to authenticate to the Systems Manager control plane and to open the bidirectional websocket channel required for Session Manager. Without these IAM permissions, even a technically healthy instance will be unable to register with Systems Manager or start a session.

  • ✗

    The EC2 instance must be in a public subnet.

    Why it's wrong here

    Session Manager does not require the instance to reside in a public subnet. The SSM Agent initiates an outbound HTTPS/TLS connection to the Systems Manager endpoints, which can traverse through a private subnet via a NAT gateway or an Amazon-provided VPC endpoint for Systems Manager. As long as the outbound path exists, the instance can be fully private and still support Session Manager sessions.

  • ✗

    The EC2 instance must have a public IP address.

    Why it's wrong here

    A public IP address is not a prerequisite for Session Manager because the service does not rely on inbound connections to the instance. Instead, the SSM Agent establishes an outbound connection over TLS to the Systems Manager regional endpoint, and the interactive session data is multiplexed over that same network connection. This design allows instances with only private IP addresses to be managed securely, provided they have network access to the SSM endpoint.

  • ✗

    The security group must allow inbound SSH from 0.0.0.0/0.

    Why it's wrong here

    The Session Manager feature intentionally does not require the security group to allow inbound SSH traffic on port 22. Unlike traditional bastion-host or direct SSH access, Session Manager avoids any inbound ports because the instance agent opens the communication channel outbound to AWS. Therefore, restricting or closing inbound SSH is not an obstacle, and in fact removing broad inbound SSH rules is a key security benefit of using Session Manager.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.