🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 6 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A company runs its public-facing web application on an Auto Scaling group of Amazon Linux 2 EC2 instances behind an Application Load Balancer. The security team requires that critical OS security patches reach all web-tier instances within 48 hours of AWS release. Operations wants minimal downtime and administration. Which approach best fulfills these needs?

  • Enable Amazon Inspector Classic assessments and turn on automatic remediation so that findings trigger patch installation on the affected instances.

  • Rely on Amazon EC2 Auto Recovery to restart failed instances from the existing AMI, ensuring the fleet remains healthy without additional patching processes.

  • Configure AWS Systems Manager Patch Manager with a security-only patch baseline, tag the Auto Scaling instances with PatchGroup=WebTier, and schedule a maintenance window to apply patches within 48 hours of release.

  • Create a weekly AWS Lambda function that uses SSH to run yum update and reboot each EC2 instance immediately after the command completes.

ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot