AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeMedium

A DevOps team is managing a critical application that runs on Amazon EC2 instances. They use AWS Systems Manager (SSM) State Manager to enforce a baseline configuration, including installing specific agents and hardening settings. Recently, a new security patch for the operating system was released, and the team needs to apply it to all instances immediately. They want to use SSM for this, but also ensure that the patch application process is carefully controlled and does not conflict with the existing State Manager associations. Which SSM capability should they use for this ad-hoc, controlled patching without altering the State Manager baseline?

  1. ASSM Distributor
  2. BSSM Patch Manager
  3. CSSM Run Command
  4. DSSM Maintenance Windows
Show answer & explanation

Correct answer: B. SSM Patch Manager

SSM Patch Manager is specifically designed for automating the patching process for managed instances, allowing for controlled, ad-hoc patching of critical updates without interfering with State Manager's baseline configuration enforcement.

Why the other options are wrong

  • A. SSM Distributor is used to package and distribute software to managed instances, not specifically for applying OS security patches.
  • C. SSM Run Command can execute commands, but Patch Manager provides a more structured and specialized approach for OS patching, including compliance reporting and patch baselines.
  • D. SSM Maintenance Windows define times for performing potentially disruptive actions, but Patch Manager is the underlying service that performs the actual patching within those windows. It's not the primary service for *what* to do.

SSM Patch Manager

AWS Systems Manager Patch Manager automates the process of patching managed instances with security updates and other patches, allowing for defined patch baselines and controlled deployment.

  • Automates OS and application patching.
  • Supports Windows and Linux instances.
  • Integrates with Maintenance Windows for scheduling.
  • Allows defining patch baselines for compliance.

Memory trick: Patch Manager takes care of your instances' health, while State Manager keeps their core identity.

More Configuration Management and Infrastructure as Code questions