AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeEasy
A DevOps team is managing an application that runs on Amazon EC2 instances. They use AWS Systems Manager to automate operational tasks. Recently, they observed that some instances are running outdated security patches, indicating configuration drift. The team wants to ensure that all EC2 instances automatically apply required OS patches and software updates on a regular schedule without manual intervention. Which AWS Systems Manager capability is best suited for this automated patching requirement?
- ASystems Manager State Manager
- BSystems Manager Patch Manager
- CSystems Manager Run Command
- DSystems Manager Explorer
Show answer & explanationAnswer & explanation
Correct answer: B. Systems Manager Patch Manager
AWS Systems Manager Patch Manager automates the process of patching managed instances with security updates and other bug fixes. It allows defining patch baselines and scheduling patching operations for groups of instances.
Why the other options are wrong
- A. Systems Manager State Manager helps define and maintain desired state configuration, which can include patching, but Patch Manager is the dedicated, higher-level service for automated patching workflows.
- C. Systems Manager Run Command allows executing commands on instances, but Patch Manager provides a more comprehensive and automated solution for ongoing patching.
- D. Systems Manager Explorer provides an operational dashboard, not automated patching.
Systems Manager Patch Manager
An AWS Systems Manager capability that automates the process of patching managed instances with security updates and other bug fixes.
- Automates OS and application patching.
- Supports patch baselines to define approved patches.
- Allows scheduling patching operations.
Memory trick: Patch Manager mends the holes, keeping systems safe and whole.