AWS Certified SysOps Administrator SOA-C01 – Question836

An application is currently deployed on several Amazon EC2 instances that reside within a VPC. Due to compliance requirements, the EC2 instances cannot have access to the public internet. SysOps Administrators require SSH access to EC2 instances from their corporate office to perform maintenance and other administrative tasks.
Which combination of actions should be taken to permit SSH access to the EC2 instances while meeting the compliance requirements? (Choose two.)

A.
Attach a NAT gateway to the VPC and configure routing
B. Attach a virtual private gateway to the VPC and configure routing
C. Attach an internet gateway to the VPC and configure routing
D. Configure a VPN connection back to the corporate office
E. Configure an Application Load Balancer in front of the EC2 instances

Correct Answer: AD

Explanation: