QuestionQ25

Incident and Event Response

A company operates a data-ingestion application across multiple AWS accounts. The accounts belong to an organization in AWS Organizations. The company needs to monitor the application and centralize access to it. Currently, the application runs on Amazon EC2 instances in several Auto Scaling groups. The EC2 instances do not have internet access because the data is sensitive. Engineers have deployed the required VPC endpoints. The EC2 instances use a custom AMI built specifically for the application.

To maintain and troubleshoot the application, system administrators need to be able to log in to the EC2 instances. This access must be automated and centrally controlled. The company’s security team must be notified whenever the instances are accessed.

Which solution meets these requirements?

Explanation

AWS Systems Manager Session Manager provides centrally controlled access to private EC2 instances through Systems Manager endpoints, without requiring inbound SSH access or internet connectivity. Managed instances need SSM Agent and an IAM instance profile with the required Systems Manager permissions; the AmazonSSMManagedInstanceCore managed policy provides those permissions. Session Manager can store session data in Amazon S3, and S3 object-upload notifications can invoke an Amazon SNS topic for security-team notifications.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!