For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 1Question 75
    Hard1 markMultiple Choice
    Domain 1.2: Security ControlsSecurityNetworkingVPC EndpointsSystems Manager

    AWS SAP-C02 · Question 75 · Domain 1.2: Security Controls

    An architect is designing a secure, multi-account environment. They need to ensure that Amazon EC2 instances in private subnets can securely access AWS Systems Manager (SSM) without traversing the public internet. They also need to ensure that SSM access is restricted ONLY to resources within their specific AWS Organization. Which TWO configurations are required? (Select TWO)

    Answer options:

    A.

    Create Interface VPC Endpoints (AWS PrivateLink) for Systems Manager in the private subnets.

    B.

    Create a Gateway VPC Endpoint for Systems Manager.

    C.

    Attach a VPC Endpoint Policy to the Interface Endpoints that uses the aws:PrincipalOrgID condition key.

    D.

    Deploy a NAT Gateway and configure security groups to only allow traffic to SSM IP addresses.

    E.

    Use AWS Resource Access Manager (RAM) to share the SSM service with the Organization.

    F.

    Configure an SCP to deny the ssm:SendCommand action.

    How to approach this question

    Identify the private connectivity method (Interface Endpoints) and the organizational restriction method (Endpoint Policy with PrincipalOrgID).

    Full Answer

    Interface VPC Endpoints (powered by AWS PrivateLink) allow private subnets to access AWS services without the internet. To restrict access, you attach a VPC Endpoint Policy. Using the `aws:PrincipalOrgID` condition key ensures that only IAM principals from your AWS Organization can use the endpoint.

    Common mistakes

    Thinking SSM supports Gateway Endpoints.
    Question 74All questions

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 1

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01An enterprise has 50 VPCs across two AWS Regions. They need to establish transitive routing betwe...HardQ02A company uses AWS Organizations. The security team wants to ensure that no IAM user or role can ...MediumQ03An application requires a relational database with an RPO of 1 second and an RTO of less than 1 m...HardQ04A company is setting up a new multi-account environment. They want to automate the provisioning o...MediumQ05An organization wants to allocate AWS costs to specific business units. They use AWS Organization...Hard
    View all 75 questions →