Courseiva
Security and Compliance →hardMultiple Choice

SOA-C02 Security and Compliance Practice Question

A SysOps administrator discovers that an EC2 instance was compromised because the SSH key pair was leaked. The administrator wants to ensure that future access to EC2 instances is secured using a method that does not rely on static keys. Which solution should the administrator implement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use EC2 Instance Connect to connect to instances.

EC2 Instance Connect allows you to connect to EC2 instances using IAM policies and does not require managing or distributing static SSH key pairs. This eliminates the risk of key leakage. Option A (bastion host with limited IP range) still relies on SSH key pairs for authentication. Option B (create new key pair) continues to use static keys and does not address the root cause. Option C (Systems Manager Session Manager) provides secure access without keys, but it requires the SSM Agent and an IAM instance role, and is not as directly focused on SSH key replacement as EC2 Instance Connect. Therefore, Option D is the best solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a bastion host with a security group that allows SSH from a limited IP range.

    Why it's wrong here

    A bastion host with a security group allowing SSH from a limited IP range still relies on long-lived SSH key pairs for authentication. Managing and distributing private keys to authorized users creates a key-management burden and increases the risk of key leakage, and the bastion itself becomes an attractive attack target and a single point of failure. It also does not provide per-user IAM-based authorization or an audit trail of who accessed the target instance. Therefore, it does not eliminate the reliance on static keys.

  • ✗

    Create a new key pair and distribute it securely to authorized users.

    Why it's wrong here

    Generating a new key pair and distributing it securely merely replaces one static credential with another, so any leaked private key grants persistent access until it is manually rotated. There is no way to tie access to a specific IAM user or to revoke a single user's access without replacing the key for everyone. Additionally, secure distribution of private keys is operationally difficult and often results in shared keys, violating least privilege. A solution that uses temporary, IAM-issued credentials would be more secure.

  • ✗

    Use AWS Systems Manager Session Manager to connect to instances.

    Why it's wrong here

    AWS Systems Manager Session Manager is a keyless, IAM-integrated option, but it requires the SSM Agent to be installed on the instance and the instance to have network access to the Systems Manager endpoints. The default experience is an interactive shell, not a native SSH session, so workflows that depend on SSH forwarding or SCP may need additional configuration. In this scenario, EC2 Instance Connect is a better fit because it provides ephemeral SSH keys directly without requiring the SSM Agent or extra setup. If the SSM Agent is not already present, Session Manager would require additional installation and permissions.

  • ✓

    Use EC2 Instance Connect to connect to instances.

    Why this is correct

    EC2 Instance Connect uses IAM policies to authorize individual users and temporarily publishes a one-time SSH public key to the instance's metadata service. The user then SSHes with a private key that is valid for only 60 seconds, eliminating long-lived key pairs and enabling per-user audit trails. This integrates with AWS CloudTrail to record access requests and empowers administrators to revoke access instantly by changing IAM permissions. It supports both console and CLI access, making it a secure, keyless-compatible solution while preserving native SSH functionality.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.