AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A financial-services company operates hundreds of Amazon EC2 instances that are registered with AWS Systems Manager. Amazon Inspector is enabled to perform continuous vulnerability scanning. Security policy states that every software vulnerability with a severity of HIGH or CRITICAL must be remediated automatically as soon as it is detected. The solution must:

  • Patch only the affected instance, not the entire fleet.
  • Keep a detailed, tamper-resistant execution record for auditors.
  • Minimize ongoing operational overhead and follow the principle of least privilege.

Which approach satisfies these requirements?

  • Create an AWS Config custom rule that evaluates EC2 instances for missing patches. When the rule is NON_COMPLIANT, invoke a Lambda function that runs EC2 Run Command to install all available patches on every EC2 instance in the account.

  • Enable Amazon GuardDuty and configure an EventBridge rule to trigger an AWS Lambda function that stops the affected EC2 instance and replaces it with a patched AMI that is rebuilt nightly.

  • Create an Amazon EventBridge rule that matches Inspector findings with severity HIGH or CRITICAL and status ACTIVE. Set the target to an AWS Systems Manager Automation runbook that invokes the AWS-RunPatchBaseline document on the instance ID from the finding, and enable CloudWatch Logs for the Automation execution.

  • Integrate Amazon Inspector with AWS Security Hub and forward findings to an SNS topic that emails the operations team, who then run AWS-RunPatchBaseline manually on each affected instance.

AWS Certified Solutions Architect Professional SAP-C02
Continuous Improvement for Existing Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot