AWS SAP-C02 · Question 51 · Domain 3.2: Security Improvement
An architect is reviewing a legacy application running on EC2 instances. The instances have public IP addresses and are accessed directly via SSH by administrators. The architect must improve security by removing public IPs and eliminating inbound open ports, while still allowing administrators to access the instances securely. Which TWO actions should be taken? (Select TWO)
Answer options:
Deploy a Bastion Host in a public subnet.
Move the EC2 instances to private subnets.
Configure AWS Client VPN to access the instances.
Use AWS Systems Manager Session Manager to access the instances.
Use EC2 Instance Connect.
Attach an Elastic IP to each instance.
75 questions · hints · full answers · grading