A company has two AWS accounts, each containing one VPC. The first VPC has a VPN connection with its corporate network. The second VPC, without a VPN, hosts an Amazon Aurora database cluster in private subnets. Developers manage the Aurora database from a bastion host in a public subnet as shown in the image.
A security review has flagged this architecture as vulnerable, and a Security Engineer has been asked to make this design more secure. The company has a short deadline and a second VPN connection to the Aurora account is not possible.
How can the Security Engineer securely set up the bastion host?
Edgecrusher77
Highly Voted 3 years, 8 months agojustfmm
3 years, 5 months agoyqoswlyilylqw
3 years, 5 months agoChinkSantana
Highly Voted 3 years, 8 months agoRaphaello
Most Recent 1 year, 4 months agoOCHT
2 years agoITGURU51
2 years agopatou
2 years, 1 month agoDara2315
2 years, 6 months agomosquitos
2 years, 6 months agosapien45
2 years, 11 months agolotfi50
3 years, 3 months agoalghoundar
3 years, 4 months agokiev
3 years, 7 months agoAyusef
3 years, 7 months agoChauPhan
3 years, 7 months agosanjaym
3 years, 8 months agoeskimolander
3 years, 8 months agoeskimolander
3 years, 8 months agoAle_Ik
3 years, 8 months ago