ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 49 - DOP-C01 discussion

Report
Export

A company plans to stop using Amazon EC2 key pairs for SSH access, and instead plans to use AWS Systems Manager Session Manager. To further enhance security, access to Session Manager must take place over a private network only.

Which combinations of actions will accomplish this? (Choose two.)

A.
Allow inbound access to TCP port 22 in all associated EC2 security groups from the VPC CIDR range.
Answers
A.
Allow inbound access to TCP port 22 in all associated EC2 security groups from the VPC CIDR range.
B.
Attach an IAM policy with the necessary Systems Manager permissions to the existing IAM instance profile.
Answers
B.
Attach an IAM policy with the necessary Systems Manager permissions to the existing IAM instance profile.
C.
Create a VPC endpoint for Systems Manager in the desired Region.
Answers
C.
Create a VPC endpoint for Systems Manager in the desired Region.
D.
Deploy a new EC2 instance that will act as a bastion host to the rest of the EC2 instance fleet.
Answers
D.
Deploy a new EC2 instance that will act as a bastion host to the rest of the EC2 instance fleet.
E.
Remove any default routes in the associated route tables.
Answers
E.
Remove any default routes in the associated route tables.
Suggested answer: B, C
asked 16/09/2024
Fthcx Fgghn
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first