ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
Your company runs hundreds of Amazon EC2 instances in several AWS accounts. A critical vulnerability in OpenSSL has been disclosed, and security policy requires that all affected Linux instances be patched within 24 hours and that management receive a compliance report showing which hosts were updated successfully. Which approach best meets these requirements while minimizing manual effort?
Add an inbound rule to every EC2 security group that blocks TCP port 443 traffic until the vendor releases an automatic fix for the vulnerability.
Rebuild golden Amazon Machine Images (AMIs) with the patched OpenSSL library and roll them out by forcing Auto Scaling groups in each account to perform an instance refresh.
Manually SSH into each EC2 instance using a bastion host and run the distribution's package manager to install the updated OpenSSL package.
Use AWS Systems Manager Patch Manager with a centrally shared patch baseline and a maintenance window to deploy the OpenSSL update and produce compliance reports across all accounts.
AWS Systems Manager Patch Manager lets you define patch baselines, create cross-account maintenance windows, and automatically apply security updates to managed instances at scale. It also generates detailed compliance reports that list which patches were installed and which instances remain non-compliant. Re-baking AMIs and redeploying Auto Scaling groups can work but is slower and requires additional validation. Manually connecting with SSH does not scale and offers no centralized reporting. Security groups mitigate network exposure but do not remediate software vulnerabilities.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS Systems Manager Patch Manager?
Open an interactive chat with Bash
How does AWS Systems Manager Patch Manager create compliance reports?
Open an interactive chat with Bash
Why is patching critical vulnerabilities like OpenSSL important?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .