AWS Certified Solutions Architect Professional SAP-C02 Practice Question
Your company uses AWS Organizations to manage 15 member accounts. The Cloud Center of Excellence must introduce an automated configuration-management solution for several hundred Amazon EC2 instances that run both Linux and Windows. The solution must keep the AWS Systems Manager (SSM) Agent and the CloudWatch agent automatically up to date, apply a common patch baseline every Saturday at 02:00, and report compliance centrally. It also needs to extend coverage automatically to any new account that joins the organization, provide a single AWS console view that shows deployment status and configuration drift, and eliminate the need to operate any dedicated configuration-management servers. Which AWS solution meets these requirements with the LEAST operational effort?
Use AWS Systems Manager Quick Setup to deploy Host Management and patch-policy configurations across the organization.
Deploy an AWS OpsWorks for Chef Automate server in the management account and register all EC2 instances as Chef nodes.
Create AWS Config managed rules with automatic remediation actions that invoke Systems Manager Automation runbooks to install agents and patch instances.
Use AWS CloudFormation StackSets to roll out maintenance windows, patch baselines, and scheduled Run Command invocations into each member account.
AWS Systems Manager Quick Setup integrates directly with AWS Organizations. Quick Setup can:
Enable the Default Host Management Configuration, which keeps SSM Agent and (optionally) the CloudWatch agent current on every managed EC2 instance across all member accounts and Regions.
Create patch policies that use Patch Manager and State Manager to apply a prescribed patch baseline on a defined schedule (for example, every Saturday at 02:00) while centrally recording patch-compliance results.
Automatically deploy the same configuration to any new account that is added to the organization and display roll-out status and drift in the Quick Setup dashboard.
Because Quick Setup is a fully managed Systems Manager capability, there are no Chef/Puppet servers or other infrastructure to maintain.
CloudFormation StackSets (distractor) can push templates cross-account, but you must design, operate, and update the templates yourself, and you must still configure maintenance windows, patch baselines, and compliance reporting manually.
AWS OpsWorks for Chef Automate (distractor) requires running and patching a Chef server, and the managed service reached end of life in May 2024.
AWS Config rules with auto-remediation (distractor) detect and remediate drift but do not provide a turnkey way to keep SSM/CloudWatch agents current or to schedule fleet-wide patching; they also require authoring rules and remediation documents per account.
Therefore, Systems Manager Quick Setup is the most operationally efficient choice.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS Systems Manager Quick Setup?
Open an interactive chat with Bash
How does AWS Systems Manager Quick Setup manage patching for EC2 instances?
Open an interactive chat with Bash
What are the main advantages of using AWS Systems Manager Quick Setup over alternatives like AWS OpsWorks or CloudFormation StackSets?
Open an interactive chat with Bash
AWS Certified Solutions Architect Professional SAP-C02
Continuous Improvement for Existing Solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access