Q386.A startup company hosts a fleet of Amazon EC2 instances in private subnets using the latest Amazon Linux 2 AMI. The company's engineers rely heavily on SSH access to the instances for troubleshooting.The company's existing

欢迎免费使用小程序搜题/刷题/查看解析,提升学历,成考自考报名,论文代写、论文查重请加客服微信skr-web


Q386.A startup company hosts a fleet of Amazon EC2 instances in private subnets using the latest Amazon Linux 2 AMI. The company's engineers rely heavily on SSH access to the instances for troubleshooting.The company's existing architecture includes the following:--A VPC with private and public subnets and a NAT gateway--Site-to-Site VPN for connectivity with the on- premises environment--EC2 security groups with direct SSH access from the on- premises environmentThe company needs to increase security controls around SSH access and provide auditing of commands executed by the engineers.Which strategy should a solutions architect use?

A.Install and configure EC2 Instance Connect on the fleet of EC2 instances. Remove all security group rules attached toEC2 instances that allow inbound TCP on port 22. Advise the engineers to remotely access the instances by using theEC2 Instance Connect CLI.
B.Update the EC2 security groups to only allow inbound TCP on port 22 to the IP addresses of the engineer's devices.Install the Amazon CloudWatch agent on all EC2 instances and send operating system audit logs to CloudWatch Logs.
C.Update the EC2 security groups to only allow inbound TCP on port 22 to the IP addresses of the engineer's devices .Enable AWS Config for EC2 security group resource changes. Enable AWS Firewall Manager and apply a security group policy that automatically remediates changes to rules.
D.Create an IAM role with the AmazonSSMManagedInstanceCore managed policy attached. Attach the IAM role to all the EC2 instances. Remove all security group rules attached to the EC2 instances that allow inbound TCP on port 22.
Have the engineers install the AWS Systems Manager Session Manager plugin
For their devices and remotely access the instances by using the start-session API call from Systems Manager.
正确答案D
访客
邮箱
网址

通用的占位符缩略图

人工智能机器人,扫码免费帮你完成工作


  • 自动写文案
  • 自动写小说
  • 马上扫码让Ai帮你完成工作
通用的占位符缩略图

人工智能机器人,扫码免费帮你完成工作

  • 自动写论文
  • 自动写软件
  • 我不是人,但是我比人更聪明,我是强大的Ai
Top