A DevOps engineer must give several external contractors access to a legacy application running on an Amazon Linux Amazon EC2 instance. The application server is reachable only within a private subnet. The contractors are not permitted to use VPN access.
What should the DevOps engineer do to provide the contractors access to the application server?
A Create an IAM user and SSH keys for each contractor. Add the public SSH key to the application server's SSH authorized_keys file. Instruct the contractors to install the AWS CLI and AWS Systems Manager Session Manager plugin, update their AWS credentials files with their private keys, and use the aws ssm start-session command to gain access to the target application server instance ID. B Ask each contractor to securely send their SSH public key. Add this public key to the application server's SSH authorized-keys file. Instruct the contractors to use their private key to connect to the application server through SSH. C Ask each contractor to securely send their SSH public key. Use EC2 pairs to import their key. Update the application server's SSH authorized_keys file. Instruct the contractors to use their private key to connect to the application server through SSH. D Create an IAM user for each contractor with programmatic access. Add each user to an IAM group that has a policy that allows the ssm:StartSession action. Instruct the contractors to install the AWS CLI and AWS Systems Manager Session Manager plugin, update their AWS credentials files with their access keys, and use the aws ssm start-session to gain access to the target application server instance ID. Show Answer Answer Explanation AWS Systems Manager Session Manager enables IAM-authorized users to start sessions with managed EC2 instances, including instances that do not accept inbound SSH connections. An IAM user with programmatic access, credentials configured for the AWS CLI, and permission for ssm:StartSession can use the Session Manager plugin and aws ssm start-session to access the target instance. SSH keys alone do not create a network path to an instance confined to a private subnet.
Learn more
Community Discussion