AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeHard

A company is implementing a new CI/CD pipeline for their applications deployed on Amazon EC2 instances. They want to ensure that all EC2 instances are patched with the latest security updates regularly and automatically. Furthermore, the patching process must be non-disruptive to the running application and allow for a controlled rollout across different environments (dev, test, prod). Which AWS service combination, integrated with their CI/CD pipeline, provides the MOST robust solution for this requirement?

  1. AAWS Health events triggering Lambda functions to apply patches.
  2. BCustom shell scripts executed via SSH during a scheduled cron job.
  3. CAWS Systems Manager Patch Manager with Maintenance Windows and State Manager.
  4. DAWS CodeDeploy for deploying new AMIs with pre-patched instances.
Show answer & explanation

Correct answer: C. AWS Systems Manager Patch Manager with Maintenance Windows and State Manager.

AWS Systems Manager Patch Manager, combined with Maintenance Windows, provides a robust solution for automated and controlled patching. Patch Manager defines patch baselines, Maintenance Windows schedule when patching occurs to minimize disruption, and State Manager can be used to apply the patches. This combination allows for non-disruptive, scheduled, and auditable patching across environments, integrating well into a CI/CD pipeline for compliance and automation.

Why the other options are wrong

  • A. AWS Health events are for service events; they don't directly facilitate automated patching of EC2 instances, and Lambda functions would require extensive custom logic to replicate Patch Manager's capabilities.
  • B. Custom shell scripts are difficult to scale, manage, audit, and provide controlled rollouts, leading to operational overhead and potential inconsistencies.
  • D. While deploying new AMIs (immutable infrastructure) is a valid strategy, the question specifically asks for patching *running* instances and a controlled rollout, which Patch Manager directly addresses. Immutable infrastructure is a different operational model.

SSM Patch Manager with Maintenance Windows

AWS Systems Manager Patch Manager automates the patching of EC2 instances, and Maintenance Windows allow scheduling these operations during non-peak hours to minimize disruption.

  • Automates OS and application patching.
  • Schedules patching during defined windows.
  • Ensures compliance and reduces security vulnerabilities.

Memory trick: Patch Manager schedules the fix, Maintenance Window keeps the doors open.

More Configuration Management and Infrastructure as Code questions