Question 1 · choose 1
About 600 Linux and Windows Server instances, all managed by AWS Systems Manager, run in four accounts and two AWS Regions of an AWS Organizations organization. The operations team must scan them for missing patches every day, install approved patches only on Sundays at 02:00, and manage the setup from one place. What should the team configure?
- AA Patch Manager patch policy in Quick Setup with daily scans and weekly installs
- BAmazon Inspector scanning of the EC2 instances in every account and Region
- CA State Manager association that runs the AWS-UpdateSSMAgent document every Sunday
- DAn EC2 Image Builder pipeline that rebuilds the AMIs every Sunday at 02:00
Show the answer and why
AA Patch Manager patch policy in Quick Setup with daily scans and weekly installs
Correct
AWS recommends patch policies. One policy can cover accounts and Regions across an organization, with separate schedules for scanning and installing.
BAmazon Inspector scanning of the EC2 instances in every account and Region
Incorrect
Inspector scans workloads for software vulnerabilities and creates findings. It does not install patches.
CA State Manager association that runs the AWS-UpdateSSMAgent document every Sunday
Incorrect
AWS-UpdateSSMAgent updates the SSM Agent itself, not the operating system and its packages.
DAn EC2 Image Builder pipeline that rebuilds the AMIs every Sunday at 02:00
Incorrect
Image Builder produces new images on a schedule. The running instances would not be patched.
Patch policies in Quick Setup are AWS's recommended way to run Patch Manager: scan and install schedules, patch baselines and targets across an organization in one configuration.
AWS documentation