AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

A company uses Amazon Inspector to continuously scan its Amazon EC2 instances for software vulnerabilities. The security team must ensure that any critical Inspector finding automatically triggers operating-system patching on the affected instance without manual intervention. Which approach will meet this requirement while following AWS best practices?

  • Create an Amazon EventBridge rule that matches Inspector findings with severityLabel set to CRITICAL and targets the AWS Systems Manager Automation runbook AWS-RunPatchBaseline to patch the impacted instance.

  • Create an AWS Config managed rule that evaluates EC2 patch compliance and sets an automatic remediation action to install missing patches whenever Inspector reports a critical vulnerability.

  • Define a Systems Manager Patch Manager maintenance window that runs daily and enable Inspector scans on the same schedule, relying on the maintenance window to patch any instances with new critical findings.

  • Configure Amazon Inspector to publish findings to an SNS topic, then subscribe each EC2 instance to the topic so the instance runs yum update or apt-get upgrade when it receives a notification.

AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot