Install the CloudWatch agent to publish disk metrics and add a disk space alarm as a patching safety control
A company has a fleet of Amazon EC2 instances that run Linux in a single AWS account. The company is using an AWS Systems Manager Automation task across the EC2 instances. During the most recent patch cycle, several EC2 instances went into an error state because of insufficient available disk space. A DevOps engineer needs to ensure that the EC2 instances have sufficient available disk space during the patching process in the future. Which combination of steps will meet these requirements? (Choose two.)
Community Votes
100% of anonymous learners picked answer AD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The CloudWatch agent is the managed way to collect disk metrics from the instances themselves, which is what makes the disk data available to CloudWatch at all (A). The alarm built on that metric is what converts monitoring into a control, and adding it as a safety control to the Automation task is what stops a patch run from proceeding on an instance that lacks disk space (D). Together they prevent the failure state from recurring rather than merely reporting it afterward.
Several instances entered an error state during patching because of insufficient disk space, so disk availability must be known ahead of the patch run and enforced as a gate. The Amazon CloudWatch agent, installed on all instances, collects disk usage metrics and publishes them to CloudWatch. A CloudWatch alarm monitoring available disk space across the instances is then added to the Systems Manager Automation task as a safety control, so patching does not proceed while disk space is insufficient.
Creating a cron job on each instance that writes disk space into a CloudWatch log stream (B and C) — this requires maintaining a script and a cron schedule on every instance and parsing logs to derive a metric, whereas the CloudWatch agent publishes disk metrics directly with no per-instance scripting. Creating a Lambda function that periodically evaluates each instance's log stream (E) — this adds a function to maintain and still depends on the cron-and-log path rather than native metrics.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The patching failures were caused by insufficient disk space, so the solution must both make disk usage observable and prevent the Automation run from proceeding when space is inadequate. Installing the Amazon CloudWatch agent on all EC2 instances provides the metric collection, since the agent reports disk utilization for the instances and publishes it to CloudWatch without any per-instance scripting (A). A CloudWatch alarm on available disk space then evaluates that metric for all instances, and adding the alarm as a safety control on the Systems Manager Automation task means the run is blocked or gated when the alarm is in the ALARM state, which prevents instances from entering the error state in the first place (D). A and D together convert a reactive failure into a preventive control.Why the Other Options Are Wrong
B installs a cron job on each EC2 instance to delete temporary files. This is a cleanup measure rather than a control, it does nothing to observe or enforce available disk space, and it requires distributing and maintaining a script on every instance. C creates a CloudWatch log group and a cron job that writes available disk space into a log stream per instance, which requires per-instance scripting and then parsing text logs to derive a metric, whereas the CloudWatch agent publishes disk metrics natively. E creates a Lambda function that periodically checks disk space by evaluating each instance's log stream, which adds a function to operate and still depends on the cron-plus-log path instead of using native metrics. dkp noted that the agent's configuration supports custom metrics for disk usage, making the cron approach unnecessary. A and D are the correct combination.Community Comment Notes
Community voted A,D unanimously. Nano803 linked the AWS Management Tools blog post describing exactly this solution, avoiding patching failures due to low disk space with Systems Manager Automation and CloudWatch alarms. trungtd explained that the agent collects system-level metrics including disk usage and sends them to CloudWatch. dkp noted the agent can be configured with custom metrics for disk usage so no cron job is needed to pipe the data, and Seoyong pointed out that the alarm depends on the agent having published the disk information. All five commentators chose the same pair.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →