Use Systems Manager Inventory with AWS Config rules to identify prohibited applications
A company uses Amazon EC2 as its primary compute platform. A DevOps team wants to audit the company's EC2 instances to check whether any prohibited applications have been installed on the EC2 instances. Which solution will meet these requirements with the MOST operational efficiency?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Systems Manager Inventory supplies the installed-software inventory and AWS Config supplies the continuous, managed evaluation against it, so together they express the audit as declarative rules rather than code (B). Option A adds resource data sync into S3 plus a Lambda function triggered by new objects, which introduces a bespoke pipeline and a function to maintain. Option C attempts to filter CloudTrail for Inventory events, but CloudTrail records API calls rather than the inventory contents, so prohibited applications would not be visible there. Option D replaces the managed inventory with CloudWatch Logs and a script run across all instances.
Auditing which applications are installed across a fleet is exactly what Systems Manager Inventory collects, and AWS Config can evaluate that inventory continuously through rules. Configuring Systems Manager on the instances, using Systems Manager Inventory as the data source, and creating AWS Config rules that monitor the inventory for prohibited applications turns the audit into a managed, continuous control without deploying any custom collection or scanning code to each instance.
Filtering a CloudTrail trail for Systems Manager Inventory events (C) — CloudTrail records management API activity, such as calls to the Systems Manager API, not the software inventory contents on each instance, so prohibited applications cannot be identified from it. Using resource data sync to S3 with a Lambda function triggered by new objects (A) — this builds a custom collection and processing pipeline when Systems Manager Inventory plus a Config rule delivers the same result as managed configuration. Running a script across all instances that writes to CloudWatch Logs and alarming on filter patterns (D) — this requires distributing and maintaining a script on every instance rather than using the agent's built-in inventory.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement is to audit the EC2 fleet for prohibited installed applications with the most operational efficiency. AWS Systems Manager Inventory is the managed feature for collecting software inventory from instances, so it is configured on each instance as the data source. AWS Config can then evaluate that inventory continuously through rules that check for prohibited applications, which expresses the audit as declarative managed configuration rather than code, and Config evaluates on an ongoing basis so drift is caught without anyone running a scan (B). Using the two services together avoids deploying any custom collection or analysis code to the fleet, which is what makes it the most operationally efficient option. B is the correct answer.Why the Other Options Are Wrong
A configures Systems Manager and Inventory but then adds Systems Manager resource data sync to synchronize and store findings in Amazon S3, plus an AWS Lambda function that runs when new objects are added to that bucket to identify prohibited applications. This introduces a bespoke export-and-process pipeline, an S3 bucket of intermediate data, and a function to operate, all of which must be maintained, when Inventory plus a Config rule already covers the requirement declaratively. C configures Systems Manager and Inventory but then filters a CloudTrail trail for Systems Manager Inventory events. CloudTrail records management API activity such as PutInventory calls; it does not contain the installed-software inventory contents of each instance, so prohibited applications cannot be identified by filtering it. D designates CloudWatch Logs as the log destination, runs an automated script across all instances to build an inventory of installed applications, forwards results to CloudWatch Logs, and alarms on filter patterns. This requires distributing, running, and maintaining a script on every instance rather than using the agent's built-in inventory, which is the opposite of operational efficiency. B is correct.Community Comment Notes
Community voted B unanimously. jamesf identified the keywords as AWS Systems Manager, Systems Manager Inventory, and an AWS Config rule, which matches the three components of option B. limelight04 restated option B's three components as the supporting combination. getadroit cited the AWS Management Tools blog post on preventing blacklisted applications with Systems Manager and AWS Config, which is exactly this design. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →