Bastion Host Flashcards

1
Q

Is the bastion host located in a public or private subnet?

A

In the public subnet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does a bastion host allow you to do?

A

allows you to connect to your EC2 instances in a private subnet using RDP or SSH

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How is a bastion host used?

A

Log into the bastion host from your desktop. Then from the bastion host, log into your EC2 instances that reside in the private subnet.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a common nickname given to bastion hosts?

A

jump box

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

True or False: It’s best practice to allow all IP addresses to reach your bastion host so you can work from anywhere?

A

False. Lock down the host to only known IP addresses.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the two most likely ports that should be open to a bastion host?

A

22 (SSH), 3389(RDP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the difference between SSH and RDP

A
  • SSH is most common for Linux command line access

- RDP allows for access to an OS user interface in Linux or Windows.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

True or False: You connect to a bastion host over the internet?

A

True: Since the Bastion host lives in a public subnet, it can be reached from the internet. Follow security best practices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Does a Bastion host allow your private subnet instances outbound access to the internet?

A

No. Bastion does not enable outgoing requests from instances.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly