Using Systems Manager to Configure Instances
Earlier in the chapter, you saw how one of the components of the Systems Manager service, Session Manager, could be used in lieu of a bastion server to connect to remote EC2 instances. Systems Manager has many other uses when it comes to managing your AWS environment, especially for a security engineer.
AWS Systems Manager is a powerful tool that allows you to easily and quickly administer and perform operational actions against your instances (both Windows- and Linux-based) at scale for both on-premises resources and within AWS without having to SSH or RDP to those instances. From a security standpoint, being able to remove these protocols from security groups reduces the attack surface of your instances even further. A single dashboard providing this administration also allows you greater infrastructure visibility. You will, for example, be able to see system configurations, the patching levels of your instances, and other software...