Q37: Secure, Keyless EC2 Access with Systems Manager Session Manager
A company needs a repeatable, low-overhead, native-AWS way to securely access and administer many EC2 instances remotely.
A company needs a repeatable, low-overhead, native-AWS way to securely access and administer many EC2 instances remotely.
An application storing data in S3 buckets across two Regions must encrypt and decrypt everything with the exact same customer managed KMS key, with the least operational overhead.
A development team runs resource-intensive tests once a month for 48 hours on an RDS for MySQL instance, and wants to cut costs without reducing the instance's compute and memory.
A VoIP service using UDP, deployed across multiple Regions behind Auto Scaling groups, needs to route users to the lowest-latency Region with automated failover between Regions.
A company managing multiple accounts via AWS Organizations needs single sign-on across all accounts, while continuing to manage users and groups in its self-managed on-premises Active Directory.
A product manager without an AWS account needs periodic access to a CloudWatch dashboard, following the principle of least privilege.
A company needs to ensure its S3 buckets do not have unauthorized configuration changes, as part of reviewing its AWS Cloud deployment.
A Lambda function receiving data via API Gateway and writing to Aurora PostgreSQL needed significantly increased quotas during proof-of-concept. The architect needs better scalability with minimal configuration effort.
EC2 costs increased due to unwanted vertical scaling of some instance types. The architect needs a graph comparing the last two months of costs, with an in-depth root-cause analysis.
Backup files are accessed frequently for the first month, then never again, but must be kept indefinitely. The company wants the most cost-effective storage solution.