Create a State Manager association with a tag query so new Auto Scaling instances are configured automatically
An Amazon EC2 Auto Scaling group manages EC2 instances that were created from an AMI. The AMI has the AWS Systems Manager Agent installed. When an EC2 instance is launched into the Auto Scaling group, tags are applied to the EC2 instance. EC2 instances that are launched by the Auto Scaling group must have the correct operating system configuration. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
State Manager is the mechanism that maintains a desired state on a defined set of managed nodes, and a tag-based target query is what makes it track the Auto Scaling group, because every instance the group launches receives those tags and is therefore captured by the association automatically (B). Options A and C rely on Run Command or a maintenance window, which are one-time or scheduled executions: they would not apply configuration to instances launched later, so new instances could start with the wrong configuration. Option D is a patching workflow rather than a configuration mechanism.
The instances must have the correct operating system configuration from the moment the Auto Scaling group launches them, and the group applies tags to every instance it launches. A Systems Manager State Manager association links the Systems Manager command document that performs the configuration, and a tag query targeting the tags the Auto Scaling group applies means the association automatically selects every current and future instance carrying those tags. Because the association is continuously evaluated, newly launched instances are configured without any manual intervention.
Using a Systems Manager Run Command document invoked by Systems Manager Compliance when instances are not compliant with the most recent patches (A) — Compliance is patch-oriented, so this ties the configuration to patch state rather than to instance membership, and Run Command is a one-time execution that does not automatically target instances launched later. Using a Run Command task registered against a daily maintenance window (C) — a maintenance window runs on a schedule, so an instance launched after the window ran would not be configured until the next daily run, leaving a window in which it runs with the wrong configuration. Using a Patch Manager patch baseline and patch group plus a command document invoked through Run Command (D) — Patch Manager manages operating system patching rather than the general configuration described, and invoking a document through Run Command is again a one-time execution rather than continuous enforcement.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement is that instances launched by the Auto Scaling group have the correct operating system configuration, which means the mechanism must automatically apply to instances the group launches in the future and not only to those running today. AWS Systems Manager State Manager defines a desired state for a set of managed nodes and continuously enforces it by means of an association, and the association's target selection here is a tag query. Because the Auto Scaling group applies tags to every instance it launches, a tag query matching those tags automatically selects both the current instances and every instance added later, and the association invokes the linked Systems Manager command document to apply the required configuration (B). chinchin97 summarized this well, noting that State Manager ensures instances launched by the Auto Scaling group automatically receive the desired configuration. B is the correct answer.Why the Other Options Are Wrong
A creates a Systems Manager Run Command document that configures the desired instance configuration and sets up Systems Manager Compliance to invoke that document when instances are not compliant with the most recent patches. Two problems exist. Systems Manager Compliance evaluates patch compliance, so tying this configuration action to patch state means it would not run for instances that are compliant on patches but lack the required configuration. In addition, Run Command is a one-time execution against selected targets, so instances launched later would not be configured. B uses a State Manager association linked to the Systems Manager command document with a tag query that runs immediately. The association is the continuously evaluated construct, and the tag query selects every instance carrying the Auto Scaling group's tags including future ones, so newly launched instances are configured automatically; this is what chinchin97 and limelight04 both emphasized. C creates a Systems Manager Run Command task with the desired configuration, creates a daily maintenance window, registers the task against the window, and designates targets. Because a maintenance window runs on a schedule, an instance launched after the window executed would remain unconfigured until the next daily run, which violates the requirement that instances must have the correct configuration. D creates a Patch Manager patch baseline and patch group using the same tags, registers the patch group with the baseline, and defines a command document invoked through Run Command. Patch Manager manages operating system patching rather than the general configuration the requirement describes, and Run Command is again a one-time execution. B is correct.Community Comment Notes
Community voted B unanimously. limelight04 explained that State Manager allows the team to define a desired state for the instances and that the association maintains it. chinchin97 added the key point that State Manager ensures all instances launched by the Auto Scaling group automatically receive the desired configuration, which applies immediately when instances launch, even though the stated focus of this question is configuration rather than patching. Kushab94 simply restated option B's two steps. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →