Question 1 · choose 1
A company has 2,000 managed nodes, Amazon EC2 instances and on-premises servers, spread across 60 accounts and four AWS Regions in one organization. All nodes must be scanned daily and patched weekly against a defined baseline, and the operations team wants one configuration for the whole organization instead of setting up each account and Region. What should the DevOps engineer do?
- ACreate a maintenance window with an AWS-RunPatchBaseline task in every account and Region, deployed by a StackSet
- BCreate an EC2 Image Builder pipeline that bakes patched AMIs weekly and replace the instances from the new AMIs
- CCreate one Quick Setup patch policy for the organization with scan and install schedules and the patch baseline
- DRun AWS-RunPatchBaseline with Run Command from the management account every week, targeting every node by tag
Show the answer and why
ACreate a maintenance window with an AWS-RunPatchBaseline task in every account and Region, deployed by a StackSet
Incorrect
This works but means a maintenance window and task in each of 240 account and Region pairs, which is the per-account setup the team wants to avoid.
BCreate an EC2 Image Builder pipeline that bakes patched AMIs weekly and replace the instances from the new AMIs
Incorrect
New AMIs do not patch running on-premises servers, and replacing every instance weekly is not a scan-and-patch process.
CCreate one Quick Setup patch policy for the organization with scan and install schedules and the patch baseline
Correct
A patch policy defines the schedule and baseline, and a single patch policy configuration can cover all accounts and Regions in an organization.
DRun AWS-RunPatchBaseline with Run Command from the management account every week, targeting every node by tag
Incorrect
Run Command performs one-time changes when someone starts it. Running it weekly in every account and Region, plus daily scans, would need custom scheduling around it.
Quick Setup patch policies turn Patch Manager into one organization-wide configuration: the baseline and the scan and install schedules apply to the chosen accounts and Regions. Nodes must be managed nodes for the policy to reach them.
AWS documentation