AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeMedium
A DevOps team is managing an application that runs on Amazon EC2 instances. They use AWS Systems Manager State Manager to ensure consistent configuration across their fleet. A recent security audit requires that all EC2 instances must have a specific anti-malware agent installed and running, and its configuration file checked daily for compliance. How can the team achieve this using AWS Systems Manager?
- AUse SSM Patch Manager to deploy the anti-malware agent and its configuration.
- BDevelop a custom AMI with the anti-malware agent pre-installed and launch instances from it.
- CCreate an SSM Automation document to install the agent and run it as a scheduled task.
- DConfigure an SSM State Manager association with a 'Run Command' document to install the agent and a 'Compliance' document to check the configuration.
Show answer & explanationAnswer & explanation
Correct answer: D. Configure an SSM State Manager association with a 'Run Command' document to install the agent and a 'Compliance' document to check the configuration.
SSM State Manager is ideal for maintaining a desired state. An association can be configured to use a 'Run Command' document to initially install the agent and then a 'Compliance' document (or a custom script executed via Run Command) to verify its configuration daily, ensuring ongoing compliance.
Why the other options are wrong
- A. SSM Patch Manager is primarily for operating system and application patching, not for installing and managing specific anti-malware agents and their custom configurations.
- B. While a custom AMI ensures initial installation, it doesn't ensure ongoing configuration compliance or daily checks, and requires AMI updates for agent version changes.
- C. SSM Automation documents are for predefined workflows; while they can install, State Manager associations are better suited for continuous desired state enforcement.
SSM State Manager
An AWS Systems Manager capability that allows you to define and maintain a desired state for your EC2 instances and on-premises servers. It ensures consistency across your infrastructure.
- Uses associations to apply desired configurations.
- Can execute Run Command, Automation, or custom scripts.
- Supports scheduling and compliance reporting.
- Helps prevent configuration drift.
Memory trick: To keep EC2s 'Stately', use 'Manager' to 'Associate' commands for 'Compliance'.