Skip to content
BytePatterns

SOA-C03 · Domain 3: Deployment, Provisioning, and Automation · 22% of the exam

Task 3.2: Automate the management of existing resources.

Running a fleet without logging in to it: Systems Manager for commands, patching, inventory and configuration, and event-driven automation with EventBridge, S3 Event Notifications and Lambda.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

About 600 Linux and Windows Server instances, all managed by AWS Systems Manager, run in four accounts and two AWS Regions of an AWS Organizations organization. The operations team must scan them for missing patches every day, install approved patches only on Sundays at 02:00, and manage the setup from one place. What should the team configure?

  1. AA Patch Manager patch policy in Quick Setup with daily scans and weekly installs
  2. BAmazon Inspector scanning of the EC2 instances in every account and Region
  3. CA State Manager association that runs the AWS-UpdateSSMAgent document every Sunday
  4. DAn EC2 Image Builder pipeline that rebuilds the AMIs every Sunday at 02:00
Show the answer and why
  • AA Patch Manager patch policy in Quick Setup with daily scans and weekly installs

    Correct

    AWS recommends patch policies. One policy can cover accounts and Regions across an organization, with separate schedules for scanning and installing.

  • BAmazon Inspector scanning of the EC2 instances in every account and Region

    Incorrect

    Inspector scans workloads for software vulnerabilities and creates findings. It does not install patches.

  • CA State Manager association that runs the AWS-UpdateSSMAgent document every Sunday

    Incorrect

    AWS-UpdateSSMAgent updates the SSM Agent itself, not the operating system and its packages.

  • DAn EC2 Image Builder pipeline that rebuilds the AMIs every Sunday at 02:00

    Incorrect

    Image Builder produces new images on a schedule. The running instances would not be patched.

Patch policies in Quick Setup are AWS's recommended way to run Patch Manager: scan and install schedules, patch baselines and targets across an organization in one configuration.

Question 2 · choose 2

A security review requires the removal of an SSH bastion host. Engineers must instead open shell sessions with AWS Systems Manager Session Manager on Amazon EC2 instances in private subnets that have no route to the internet. SSM Agent is installed on the instances, and the account does not use the Default Host Management Configuration. Which actions are required? (Choose TWO.)

  1. AAttach an instance profile whose role includes the AmazonSSMManagedInstanceCore policy
  2. BCreate interface VPC endpoints for ssm, ssmmessages and ec2messages in the VPC
  3. CAllow inbound TCP port 22 from the VPC CIDR block in the instances' security group
  4. DAssociate an Elastic IP address with each instance
  5. ECreate an EC2 key pair and give the private key to each engineer
Show the answer and why
  • AAttach an instance profile whose role includes the AmazonSSMManagedInstanceCore policy

    Correct

    Without the account-level setting, instances get the permissions Systems Manager needs through an instance profile with this managed policy.

  • BCreate interface VPC endpoints for ssm, ssmmessages and ec2messages in the VPC

    Correct

    With these endpoints the agent reaches Systems Manager over AWS PrivateLink, so no internet gateway or NAT device is needed.

  • CAllow inbound TCP port 22 from the VPC CIDR block in the instances' security group

    Incorrect

    SSM Agent opens all connections to Systems Manager itself, and Session Manager needs no inbound ports.

  • DAssociate an Elastic IP address with each instance

    Incorrect

    An Elastic IP address is a public address for internet communication, which the private design does not want and Session Manager does not need.

  • ECreate an EC2 key pair and give the private key to each engineer

    Incorrect

    Session Manager provides node access without managing SSH keys.

Session Manager in an isolated subnet needs two things: permission for the instance to talk to Systems Manager, and a private network path to it through VPC endpoints.

Question 3 · choose 1

Every managed Amazon EC2 instance tagged Role=web must always have the CloudWatch agent installed and running with the approved configuration. If someone stops or removes the agent, it must be put back within 30 minutes without anyone acting, and new web instances must get it too. What should the operations team set up?

  1. AA Run Command execution of the agent installation document on all instances that have the tag
  2. BA State Manager association on Role=web that applies the agent every 30 minutes
  3. CAn AWS Config rule that reports web instances without the agent as noncompliant
  4. DAn EventBridge rule for EC2 state changes that emails the team when a web instance starts
Show the answer and why
  • AA Run Command execution of the agent installation document on all instances that have the tag

    Incorrect

    Run Command performs one-time changes. Agents stopped or removed later, and new instances, would not be handled.

  • BA State Manager association on Role=web that applies the agent every 30 minutes

    Correct

    An association defines a state to keep, its targets and a schedule. If software is missing or its service is stopped, State Manager can install or start it again on each run.

  • CAn AWS Config rule that reports web instances without the agent as noncompliant

    Incorrect

    A Config rule evaluates resources against the desired configuration. On its own it reports compliance and does not reinstall the agent.

  • DAn EventBridge rule for EC2 state changes that emails the team when a web instance starts

    Incorrect

    A notification only tells people about new instances; someone would still have to install the agent, and stopped agents would go unnoticed.

Keeping nodes in a defined state on a schedule is the job of State Manager; Run Command is for one-off changes.

Question 4 · choose 1

Partners upload CSV files to the incoming/ prefix of an Amazon S3 bucket. An AWS Lambda function must process each new CSV file within seconds of its arrival and write the result to the processed/ prefix of the same bucket. Other files in incoming/ must be ignored. What is the simplest correct way to invoke the function?

  1. AGenerate a daily S3 Inventory report and have the function process the new keys it lists
  2. BAn S3 Event Notification for all object-created events in the bucket, with the function skipping other keys
  3. CAn S3 Event Notification for object-created events filtered on prefix incoming/ and suffix .csv
  4. DS3 Same-Region Replication of the incoming/ prefix to a second bucket
Show the answer and why
  • AGenerate a daily S3 Inventory report and have the function process the new keys it lists

    Incorrect

    S3 Inventory produces lists on a daily or weekly basis, far from "within seconds".

  • BAn S3 Event Notification for all object-created events in the bucket, with the function skipping other keys

    Incorrect

    Every result the function writes to the same bucket would invoke it again. AWS warns about this loop and suggests limiting the trigger to the incoming prefix.

  • CAn S3 Event Notification for object-created events filtered on prefix incoming/ and suffix .csv

    Correct

    Event notifications can invoke a Lambda function directly and can be filtered by key prefix and suffix, so only new CSV files in incoming/ trigger it.

  • DS3 Same-Region Replication of the incoming/ prefix to a second bucket

    Incorrect

    Replication copies objects to another bucket. It does not invoke any processing.

Event notifications with key filters give per-object, near-immediate triggers; the prefix filter also keeps the function's own output from triggering it again.

Question 5 · choose 1

An operator uses AWS Systems Manager Run Command to run a diagnostics script on 40 Amazon EC2 instances and selects the option to write command output to an Amazon S3 bucket. The commands succeed, but no output files appear in the bucket. The operator's own IAM user is allowed s3:PutObject on the bucket. What should the operations team change?

  1. AGive the operator's IAM user the s3:PutObject permission on the bucket's prefix as well
  2. BTurn on S3 Versioning for the output bucket
  3. CAdd a bucket policy that allows the Systems Manager service principal to write to the bucket
  4. DAllow s3:PutObject on the bucket in the instance profile role of the instances
Show the answer and why
  • AGive the operator's IAM user the s3:PutObject permission on the bucket's prefix as well

    Incorrect

    The permissions used to write the output are not those of the IAM user who runs the command.

  • BTurn on S3 Versioning for the output bucket

    Incorrect

    Versioning keeps multiple versions of objects. It does not grant anyone permission to write them.

  • CAdd a bucket policy that allows the Systems Manager service principal to write to the bucket

    Incorrect

    The output is written with the credentials of the instance profile on each instance, not by a service principal.

  • DAllow s3:PutObject on the bucket in the instance profile role of the instances

    Correct

    For EC2 instances, the permissions to write command output to S3 are those of the instance profile assigned to the instance.

Run Command output is uploaded from the managed node itself, so the node's role, not the operator's, needs write access to the bucket.

Question 6 · choose 1

A team runs standalone Amazon EC2 instances with EBS root volumes. When AWS schedules a stop or retirement event for one of them, the team wants a Systems Manager Automation runbook to stop and start that instance right away, during business hours, instead of waiting for the scheduled time. No one should have to watch for the notification emails. What should the team set up?

  1. AAn EventBridge rule on AWS Health scheduled-event notices that targets the runbook
  2. BA CloudWatch alarm on StatusCheckFailed_System with an EC2 recover action
  3. CDetailed monitoring on each instance so that metrics arrive every minute
  4. DAn EventBridge rule that matches EC2 Instance State-change Notification events for the stopped state
Show the answer and why
  • AAn EventBridge rule on AWS Health scheduled-event notices that targets the runbook

    Correct

    AWS sends an AWS Health event for scheduled instance events, and EventBridge rules on Health events can start corrective actions such as operations on the affected EC2 instances.

  • BA CloudWatch alarm on StatusCheckFailed_System with an EC2 recover action

    Incorrect

    The recover action responds after a system status check has already failed. A scheduled event is announced in advance, before anything fails.

  • CDetailed monitoring on each instance so that metrics arrive every minute

    Incorrect

    Detailed monitoring shortens metric periods. Scheduled events are not metrics, and nothing would run the runbook.

  • DAn EventBridge rule that matches EC2 Instance State-change Notification events for the stopped state

    Incorrect

    State-change events report a stop when it happens. The rule would fire only at the scheduled time, which is what the team wants to avoid.

Scheduled maintenance reaches you as an AWS Health event as well as an email. An EventBridge rule on that event turns it into automation.

Practise domain 3 →Practise all domains →