ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
Your company will launch an Auto Scaling group for an internal web app that must meet CIS Level-1 Linux benchmarks. Policy requires every instance start from an approved AMI that is already hardened and fully patched, and administrators want to minimize ongoing effort to keep that image current. Which approach best meets these needs with the least manual maintenance?
Launch instances directly from the latest Amazon Linux 2 AMI, enable unattended security updates with yum-cron, and periodically scan them with Amazon Inspector.
Configure an EC2 Image Builder pipeline that applies CIS hardening and patches on a schedule to produce a golden AMI; reference the latest AMI in the Auto Scaling launch template.
Invoke AWS Systems Manager Patch Manager from Auto Scaling lifecycle hooks to install updates, then run Ansible hardening playbooks via user-data on each instance after it launches.
Each month, manually harden a single EC2 instance, create an AMI from it, and update the Auto Scaling group to use the new image.
EC2 Image Builder can run a scheduled pipeline that applies CIS Level-1 hardening components, installs the latest OS patches, executes validation tests, and produces a fresh AMI automatically. By having the launch template reference the most-recent AMI (for example, through a Systems Manager Parameter Store alias), every new instance in the Auto Scaling group starts from this compliant, up-to-date image. Alternative methods rely on post-boot patching, extra configuration scripts, or repetitive manual hardening, which increases operational overhead and leaves a larger window of exposure.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is EC2 Image Builder?
Open an interactive chat with Bash
How does Systems Manager Parameter Store help reference the latest AMI?
Open an interactive chat with Bash
What are CIS Level-1 Linux benchmarks?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .