Replace SSH keys with Systems Manager Session Manager for secure admin access

Answer Correct answer: A — AWS Systems Manager Session Manager gives auditable, keyless remote admin for Linux and Windows instances in private subnets.

A company has a large fleet of Linux Amazon EC2 instances and Windows EC2 instances that run in private subnets. The company wants all remote administration to be performed as securely as possible in the AWS Cloud. Which solution will meet these requirements?

  1. Do not use SSH-RSA private keys during the launch of new instances Implement AWS Systems Manager Session Manager Correct Answer
  2. Generate new SSH-RSA private keys for existing instances Implement AWS Systems Manager Session Manager
  3. Do not use SSH-RSA private keys during the launch of new instances Configure EC2 Instance Connect
  4. Generate new SSH-RSA private keys for existing instances Configure EC2 Instance Connect

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Session Manager needs no inbound SSH/RDP, no managed key pairs, and logs sessions to CloudWatch/S3 for audit, covering both OS types. EC2 Instance Connect (C/D) supports only Linux, so it cannot cover the Windows fleet; generating SSH keys (B/D) keeps key-management risk. Only A meets 'most secure' for the whole mixed fleet.

A mixed Linux and Windows fleet in private subnets needs the most secure remote administration. Do not bake SSH-RSA keys into new instances; instead use AWS Systems Manager Session Manager, which provides auditable, browser-based shell access over the SSM control channel without opening inbound ports or managing SSH keys—and works for both Linux and Windows.

Choosing EC2 Instance Connect (C/D)—it supports only Linux instances, failing the Windows requirement. Generating or keeping SSH-RSA keys (B/D) reintroduces key-management and inbound-access risk that Session Manager eliminates.

Community Discussion (5 comments)

cumzle_com 👍 1 Selected: A
Answer is A SSM dont need SSH-RSA
Certified101 👍 2 Selected: A
Answer is A Definitely not C or D because EC2 Instance Connect supports only linux instances https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/connect-linux-inst-eic.html
Nash101 👍 1
A- This managed service allows secure, session-based access to EC2 instances without the need for public SSH access or pre-configured keys. Each session is temporary and auditable, enhancing security.
Zek 👍 2
Answer is A Definitely not C or D because EC2 Instance Connect supports only linux instances https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/connect-linux-inst-eic.html Session Manager provides secure and auditable node management without the need to open inbound ports, maintain bastion hosts, or manage SSH keys. Session Manager provides support for Windows, Linux, and macOS from a single tool. https://docs.aws.amazon.com/systems-manager/latest/userguide/session-manager.html
danish1234 👍 2 Selected: A
AWS SSM is for private entry in ec2 that doesnt require SSH keys

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Session Manager provides secure, auditable, session-based access to both Linux and Windows EC2 instances without requiring inbound ports, public IPs, or SSH/RSA key pairs. Because it works across the mixed fleet and centralizes auditing, it is the most secure remote-administration option.

Why the Other Options Are Wrong

C and D propose EC2 Instance Connect, which supports only Linux instances and therefore cannot cover the Windows fleet. B and D still generate SSH-RSA keys, retaining key-management and inbound-access risk. A eliminates keys entirely and covers both OS types.

Community Comment Notes

Community voted A (100). Commenters stressed Session Manager needs no SSH keys and that Instance Connect (C/D) is Linux-only, citing the EC2 Instance Connect Linux doc. A was confirmed as most secure for mixed fleets.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide