AWS Certified Solutions Architect Professional SAP-C02 Practice Question
A large enterprise is managing a hybrid environment with thousands of Amazon EC2 instances and on-premises servers. They need to enforce a standard baseline configuration across the entire fleet, which includes specific software versions and security settings. A key requirement is to automatically apply this baseline to newly launched instances and periodically scan the entire fleet for any configuration drift. If an instance is found to be non-compliant, it should be reported to a central dashboard. The solution must minimize manual intervention and use AWS native services for configuration management.
Which AWS Systems Manager capability should a solutions architect recommend to meet these requirements most effectively?
The correct answer is AWS Systems Manager State Manager. State Manager is designed to be a scalable configuration management service that automates the process of keeping managed nodes in a defined state. It uses documents to define the desired configuration and 'associations' to apply that configuration to a target set of instances on a schedule. State Manager continuously monitors the fleet for configuration drift and reports compliance status to a central dashboard, which directly addresses the key requirements of the scenario.
AWS Systems Manager Run Command is used for executing ad-hoc or on-demand commands on managed instances. While it can be used to apply a configuration once, it does not inherently maintain a persistent state or automatically scan for and remediate configuration drift over time, making it less effective for this use case than State Manager.
AWS Systems Manager Distributor is used to securely store and distribute software packages to managed instances. While it can be used as part of a configuration management solution (for example, a State Manager association could use Distributor to install a package), it does not by itself enforce the configuration or manage drift. It is a tool for package distribution, not state management.
AWS Systems Manager Patch Manager is a specialized service for automating the process of patching operating systems and applications with security and other updates. Its scope is limited to patching and does not cover general-purpose configuration management, such as installing specific software or enforcing custom security settings as required by the scenario.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS Systems Manager State Manager, and how does it work?
Open an interactive chat with Bash
How does State Manager differ from AWS Systems Manager Patch Manager?
Open an interactive chat with Bash
What is configuration drift, and how does AWS State Manager handle it?
Open an interactive chat with Bash
AWS Certified Solutions Architect Professional SAP-C02
Design for New Solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access