AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeMedium

A DevOps team is managing an application that runs on Amazon EC2 instances. They use AWS Systems Manager State Manager to ensure consistent configuration across their fleet. A recent security audit requires that all EC2 instances must have a specific anti-malware agent installed and running, and its configuration file checked daily for compliance. How can the team achieve this using AWS Systems Manager?

  1. AUse SSM Patch Manager to deploy the anti-malware agent and its configuration.
  2. BDevelop a custom AMI with the anti-malware agent pre-installed and launch instances from it.
  3. CCreate an SSM Automation document to install the agent and run it as a scheduled task.
  4. DConfigure an SSM State Manager association with a 'Run Command' document to install the agent and a 'Compliance' document to check the configuration.
Show answer & explanation

Correct answer: D. Configure an SSM State Manager association with a 'Run Command' document to install the agent and a 'Compliance' document to check the configuration.

SSM State Manager is ideal for maintaining a desired state. An association can be configured to use a 'Run Command' document to initially install the agent and then a 'Compliance' document (or a custom script executed via Run Command) to verify its configuration daily, ensuring ongoing compliance.

Why the other options are wrong

  • A. SSM Patch Manager is primarily for operating system and application patching, not for installing and managing specific anti-malware agents and their custom configurations.
  • B. While a custom AMI ensures initial installation, it doesn't ensure ongoing configuration compliance or daily checks, and requires AMI updates for agent version changes.
  • C. SSM Automation documents are for predefined workflows; while they can install, State Manager associations are better suited for continuous desired state enforcement.

SSM State Manager

An AWS Systems Manager capability that allows you to define and maintain a desired state for your EC2 instances and on-premises servers. It ensures consistency across your infrastructure.

  • Uses associations to apply desired configurations.
  • Can execute Run Command, Automation, or custom scripts.
  • Supports scheduling and compliance reporting.
  • Helps prevent configuration drift.

Memory trick: To keep EC2s 'Stately', use 'Manager' to 'Associate' commands for 'Compliance'.

More Configuration Management and Infrastructure as Code questions