AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A financial services company operates a large, hybrid fleet of thousands of Amazon EC2 instances and on-premises servers across multiple AWS Regions and data centers. A new compliance mandate requires that all servers are hardened according to Center for Internet Security (CIS) benchmarks and that security patches are applied within a strict timeframe. The security team prohibits direct SSH or RDP access to the production environment. The company needs a centralized, automated solution to enforce these configurations, report on compliance status, and automatically remediate any configuration drift. Which approach using AWS Systems Manager would be the most effective and scalable to meet these requirements?

  • Use AWS CloudFormation StackSets to deploy configuration templates to all EC2 instances. For on-premises servers, use an external configuration management tool like Ansible, integrated with Systems Manager Run Command to execute playbooks. Monitor compliance by aggregating logs from all servers.

  • Use AWS Systems Manager Run Command to execute a custom hardening script on all managed instances on a recurring schedule. Use a separate Run Command task to apply security patches. Trigger these tasks using Amazon EventBridge schedules and monitor execution logs in Amazon CloudWatch.

  • Register all servers as managed instances using the SSM Agent. Use AWS Systems Manager State Manager with an association that applies a CIS hardening document to enforce the security benchmarks. Use AWS Systems Manager Patch Manager with patch baselines and maintenance windows to automate patching. Monitor overall status using AWS Systems Manager Compliance.

  • Deploy the AWS Config agent to all servers. Create custom AWS Config rules to continuously check for CIS benchmark adherence and missing patches. For any non-compliant resources, use AWS Config remediation actions to trigger AWS Lambda functions that apply the necessary configuration changes and patches.

AWS Certified Solutions Architect Professional SAP-C02
Design for New Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot