Replace SSH keys with Systems Manager Session Manager for secure admin access
A company has a large fleet of Linux Amazon EC2 instances and Windows EC2 instances that run in private subnets. The company wants all remote administration to be performed as securely as possible in the AWS Cloud. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Session Manager needs no inbound SSH/RDP, no managed key pairs, and logs sessions to CloudWatch/S3 for audit, covering both OS types. EC2 Instance Connect (C/D) supports only Linux, so it cannot cover the Windows fleet; generating SSH keys (B/D) keeps key-management risk. Only A meets 'most secure' for the whole mixed fleet.
A mixed Linux and Windows fleet in private subnets needs the most secure remote administration. Do not bake SSH-RSA keys into new instances; instead use AWS Systems Manager Session Manager, which provides auditable, browser-based shell access over the SSM control channel without opening inbound ports or managing SSH keys—and works for both Linux and Windows.
Choosing EC2 Instance Connect (C/D)—it supports only Linux instances, failing the Windows requirement. Generating or keeping SSH-RSA keys (B/D) reintroduces key-management and inbound-access risk that Session Manager eliminates.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.