AWS Certified Solutions Architect Professional SAP-C02 Practice Question
A global enterprise has 250 AWS accounts that are organized into multiple organizational units (OUs) in AWS Organizations. Security policy mandates that every Amazon EC2 instance must automatically install any Critical or Important operating-system security patch within 24 hours of its release. The solution must provide a single place to configure and report patch compliance for all accounts and Regions, use only the existing SSM Agent, remediate non-compliant instances automatically, and impose the least possible operational overhead on the central cloud-operations team.
Which approach best meets these requirements?
Use AWS CloudFormation StackSets to deploy identical custom patch baselines, nightly maintenance windows, and AWS-RunPatchBaseline Run Command tasks in every account and Region. Tag each instance with its patch group and build a cross-account CloudWatch dashboard to display patch compliance.
Create an AWS Config conformance pack that contains the managed rule EC2_MANAGEDINSTANCE_PATCH_COMPLIANCE_STATUS_CHECK and attach an auto-remediation action that invokes the AWS-RunPatchBaseline Automation runbook on every NON_COMPLIANT instance. Run the rule once every 24 hours and aggregate the results in the management account.
Enable Amazon Inspector across the organization by delegating administration to a central account, then configure Amazon EventBridge rules that match Inspector EC2 vulnerability findings with a CVSS score of 7.0 or higher and start an SSM Automation runbook that executes AWS-RunPatchBaseline on the affected instances. Use the Inspector console for compliance visibility.
From the management account, deploy an AWS Systems Manager Quick Setup Patch Manager policy to the entire organization. Configure a custom patch baseline with a 0-day auto-approval rule for Critical and Important patches, select the Scan and install operation, and schedule the State Manager association to run daily. Quick Setup propagates the baseline, schedule, and compliance reporting across all member accounts and Regions by using the existing SSM Agent.
AWS Systems Manager Quick Setup can create a single Patch Manager policy that targets every account and Region in an organization. In the wizard the operations team chooses Scan and install, sets a daily installation schedule, and selects a custom patch baseline whose auto-approval delay is set to 0 days for Critical and Important updates. Quick Setup then uses CloudFormation StackSets to deploy a State Manager association that runs AWS-RunPatchBaselineAssociation on each managed node and continually heals configuration drift. Compliance data is aggregated automatically in Patch Manager and no additional agents are required, so day-to-day maintenance is minimal.
The Config-based alternative first detects non-compliance and then runs an Automation document for every instance, which adds rule management, remediation configuration, and periodic evaluations in every account. The Inspector-based proposal only identifies vulnerabilities; it still needs custom EventBridge and Automation logic for patching and introduces an extra paid service. Building and managing StackSets, maintenance windows, and dashboards in every account provides the same technical result but requires significantly more manual coordination and ongoing upkeep. Therefore, the Quick Setup patch policy is the most operationally efficient way to satisfy the 24-hour patching requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS Systems Manager Quick Setup and how does it help in this scenario?
Open an interactive chat with Bash
What is the purpose of a custom patch baseline with a 0-day auto-approval rule?
Open an interactive chat with Bash
How does AWS Patch Manager ensure compliance reporting across all accounts and Regions?
Open an interactive chat with Bash
AWS Certified Solutions Architect Professional SAP-C02
Continuous Improvement for Existing Solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access