Harden EC2: Enforce IMDSv2, Encrypt EBS by Default and Close SSH
Fix the three most common EC2 findings on a legacy web server. You require IMDSv2 to stop credential theft through SSRF, turn on EBS encryption by default for the Region, and remove SSH from the internet in favor of Session Manager.
Level: Advanced · Time: about 45 minutes · Region: us-east-1
AWS services you'll use
- EC2
- EBS
- Systems Manager
- VPC
What you'll do in this lab
- Require IMDSv2
- Encrypt new EBS volumes by default
- Remove SSH from the internet
- Verify the solution end to end
Each task is checked against your live AWS account. Step-by-step instructions, hints and verification unlock when you start the lab.
Before you start
- IAM policies, KMS and CloudTrail at associate level
- Comfortable with CloudShell and the AWS CLI
How the lab works
- Get a real, temporary AWS account locked to one region. No AWS account of your own needed.
- Build in the real AWS console with a guide beside it, and hints when you are stuck.
- Verify every task: we check the resources in your live account.
- Automatic cleanup: everything is deleted when you stop, and nothing is billed to you.
Questions about this lab
Do I need my own AWS account?
No. When you start the lab, Cloud Arena gives you a real, temporary AWS account with its own login, locked to one region. You work in the real AWS Management Console, not a simulator.
Will AWS charge me anything?
No. Cloud Arena pays for the AWS resources, and everything you create is deleted automatically when you stop the lab or the session ends. Nothing is billed to you by AWS.
How long does the Harden EC2: Enforce IMDSv2, Encrypt EBS by Default and Close SSH lab take?
Plan for about 45 minutes. The session timer is shown on screen, and every task is checked against your live AWS account when you click Verify.
How do I get access to this lab?
It is included in the AWS Certified Security – Specialty plan: a one-time payment for every lab in the path, 2 attempts per lab and a 7-day money-back guarantee. You can also start with the 5 free labs.
Does this lab help with the Security – Specialty (SCS-C03) exam?
Yes. It is part of the AWS Certified Security – Specialty path, which covers the hands-on skills behind the exam. Doing the task in a real account is what makes the questions easier to reason about.
Related AWS labs
- GuardDuty: Findings, Automated Alerting and Suppression Rules
- Mask Sensitive Data in CloudWatch Logs: Managed and Custom Data Identifiers
- Secrets Manager: Customer Managed Key, Rotation and Resource Policy
- Security Hub and AWS Config: Standards, Findings and Triage
- Temporary Credentials: External IDs, Presigned URLs and Session Revocation
- Enforce S3 Encryption: SSE-KMS by Default, Bucket Keys and Deny Policies