QuestionQ50

Infrastructure Security

A company operates both on-premises legacy systems and resources in AWS. The AWS resources include an Amazon DynamoDB table and an Amazon S3 bucket. The on-premises legacy systems must connect to DynamoDB and Amazon S3 regularly.

The company currently uses a bastion host in a public subnet of a VPC. The company connects to the bastion host using an SSH private key stored on-premises. The instance profile assigned to the bastion host has full access to Amazon S3 and DynamoDB.

A security team introduces a new internal policy requiring the removal of all bastion hosts. The policy requires every system to authenticate by using certificate-based authentication.

Which solution meets these requirements?

Explanation

AWS IAM Roles Anywhere lets on-premises workloads authenticate with X.509 certificates issued by a trusted certificate authority and receive temporary credentials for an IAM role. That role can grant the required Amazon DynamoDB and Amazon S3 permissions without retaining a bastion host or long-term credentials.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!