For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 6Question 51
    Medium1 markMultiple Choice
    Domain 3.2: Security ImprovementSecurityVPCSystems Manager

    AWS SAP-C02 · Question 51 · Domain 3.2: Security Improvement

    An architect is reviewing a legacy application running on EC2 instances. The instances have public IP addresses and are accessed directly via SSH by administrators. The architect must improve security by removing public IPs and eliminating inbound open ports, while still allowing administrators to access the instances securely. Which TWO actions should be taken? (Select TWO)

    Answer options:

    A.

    Deploy a Bastion Host in a public subnet.

    B.

    Move the EC2 instances to private subnets.

    C.

    Configure AWS Client VPN to access the instances.

    D.

    Use AWS Systems Manager Session Manager to access the instances.

    E.

    Use EC2 Instance Connect.

    F.

    Attach an Elastic IP to each instance.

    How to approach this question

    Identify how to make instances private and how to access them without SSH.

    Full Answer

    B, D
    Moving instances to private subnets removes public IPs. AWS Systems Manager Session Manager allows secure access to private instances without opening inbound ports, as the SSM agent makes an outbound connection to AWS.

    Common mistakes

    Choosing Bastion Hosts, which is a legacy pattern.
    Question 50All questionsQuestion 52

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 6

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A global enterprise requires highly available hybrid connectivity between its on-premises data ce...HardQ02An organization has 50 VPCs across two AWS Regions connected via Transit Gateways (TGW). The TGWs...HardQ03A company uses AWS Organizations. The network team wants to share a central Transit Gateway (TGW)...MediumQ04An enterprise has on-premises data centers in the US and Europe. They want to use the AWS global ...HardQ05A company requires that all API calls to Amazon S3 from their VPC must not traverse the public in...Medium
    View all 75 questions →