Set the Systems Manager default EC2 instance management role so new instances are managed automatically

Answer Correct answer: A — set the Systems Manager default EC2 instance management role so new instances are managed automatically.

A company uses AWS Systems Manager to manage a fleet of Amazon Linux EC2 instances that have SSM Agent installed. All EC2 instances are configured to use Instance Metadata Service Version 2 (IMDSv2) and are running in the same AWS account and AWS Region. Company policy requires developers to use only Amazon Linux. The company wants to ensure that all new EC2 instances are automatically managed by Systems Manager after creation. Which solution will meet these requirements with the MOST operational efficiency?

  1. Create an IAM role that has a trust policy that allows Systems Manager to assume the role. Attach the AmazonSSMManagedEC2InstanceDefaultPolicy policy to the role. Configure the default-ec2-instance-management-role SSM service setting to use the role. Correct Answer
  2. Ensure that AWS Config is set up. Create an AWS Config rule that validates if an EC2 instance has SSM Agent installed. Configure the rule to run on EC2 configuration changes. Configure automatic remediation for the rule to run the AWS-InstallSSMAgent SSM document to install SSM Agent.
  3. Configure Systems Manager Patch Manager. Create a patch baseline that automatically installs SSM Agent on all new EC2 instances. Create a patch group for all EC2 instances. Attach the patch baseline to the patch group. Create a maintenance window and maintenance window task to start installing SSM Agent daily.
  4. Create an EC2 instance role that has a trust policy that allows Amazon EC2 to assume the role. Attach the AmazonSSMManagedInstanceCore policy to the role. Ensure that AWS Config is set up. Use the ec2-instance-profile-attached managed AWS Config rule to validate if an EC2 instance has the role attached. Configure the rule to run on EC2 configuration changes. Configure automatic remediation for the rule to run the AWS-SetupManagedRoleOnEc2Instance SSM document to attach the role to the EC2 instance.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The requirement is that new instances become managed automatically after creation, which calls for an account-level default rather than a reactive check (A). The Systems Manager default-ec2-instance-management-role service setting is applied automatically to EC2 instances at creation, so instances never need a manual step or a Config remediation to gain the role (A). Options B, C, and D all depend on AWS Config evaluating, Patch Manager running, or an EventBridge schedule firing after the fact, so instances exist unmanaged for a period of time, which is the opposite of the automatic-at-creation requirement.

Every instance runs Amazon Linux with SSM Agent already installed and uses IMDSv2, so the only thing a new instance needs in order to be managed by Systems Manager is an IAM instance profile granting the Systems Manager permissions. Systems Manager supports a default EC2 instance management role that is automatically attached to newly created EC2 instances, so creating a role whose trust policy allows Systems Manager to assume it, attaching the AmazonSSMManagedEC2InstanceDefaultPolicy managed policy, and configuring the default-ec2-instance-management-role service setting to that role makes every new instance managed on creation with no per-instance action.

Using an AWS Config rule that validates whether SSM Agent is installed with remediation running AWS-InstallSSMAgent (B) — this installs the agent reactively after a Config evaluation, so a newly created instance is unmanaged until the rule runs and remediation completes, and the agent is already present here so installing it is not the gap. Using Patch Manager with a patch baseline, patch group, and daily maintenance window to install SSM Agent (C) — a maintenance window runs on a daily schedule, so a new instance could be unmanaged for up to a day, and installing the agent is again not the requirement. Using a Config rule with the ec2-instance-profile-attached rule and AWS-SetupManagedRoleOnEc2Instance remediation (D) — this attaches the role reactively after a Config evaluation rather than automatically at creation, so it does not meet the automatic requirement.

Community Discussion (3 comments)

Srikantha 👍 1 Selected: A
By setting the default-ec2-instance-management-role service setting, new EC2 instances will automatically assume the correct role, allowing seamless management by AWS Systems Manager. Thus, Option A is the best choice.
Ky_24 👍 2 Selected: A
1. Automatic Role Association: • AWS Systems Manager supports a default instance management role that is automatically attached to new EC2 instances upon creation. • By configuring the default-ec2-instance-management-role SSM service setting, any new EC2 instance will automatically be associated with the specified IAM role. 2. IAM Role and Policy: • The AmazonSSMManagedEC2InstanceDefaultPolicy provides the necessary permissions for SSM Agent to manage instances, including access to Systems Manager services, Amazon S3, and AWS Config logs. 3. Operational Efficiency: • This solution ensures new EC2 instances are automatically registered with Systems Manager without requiring additional manual steps or configuration changes. • It eliminates the need for AWS Config rules, patch baselines, or remediation documents, simplifying the management process.
ArunRav 👍 3 Selected: A
Amazon Linux has the agent already installed. So A perform the rest of the steps to manage the instances using SSM

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The fleet consists of Amazon Linux instances that already have SSM Agent installed and use IMDSv2, so the only remaining requirement for Systems Manager management is an IAM instance profile whose permissions allow Systems Manager to manage the instance. AWS Systems Manager provides a default EC2 instance management role that is attached automatically to EC2 instances when they are created, and an administrator configures it by creating an IAM role whose trust policy allows Systems Manager to assume it, attaching the AmazonSSMManagedEC2InstanceDefaultPolicy managed policy to that role, and then setting the default-ec2-instance-management-role Systems Manager service setting to that role (A). Once configured, every instance created afterward receives the role automatically and is managed by Systems Manager from the moment it comes up, with no per-instance action, no scheduled evaluation, and no remediation run. Ky_24 explained exactly this automatic role association, and Srikantha noted that setting the default-ec2-instance-management-role service setting means new instances automatically assume the correct role for seamless Systems Manager management. A is the correct answer.

Why the Other Options Are Wrong

B ensures AWS Config is set up, creates a Config rule validating that an EC2 instance has SSM Agent installed, runs it on configuration changes, and configures automatic remediation running AWS-InstallSSMAgent. Two problems exist. The agent is already installed on these Amazon Linux instances, so validating and installing it addresses nothing; the actual gap is the instance profile. And because the mechanism is a Config rule with remediation, it is reactive: a newly created instance is unmanaged until the configuration change is evaluated and remediation runs, which fails the requirement that instances be managed automatically after creation. C configures Systems Manager Patch Manager with a patch baseline, a patch group for all instances, and a maintenance window with a task that installs SSM Agent daily. A daily maintenance window means a newly created instance could remain unmanaged for up to a day, and Patch Manager is a patching mechanism rather than a mechanism for granting instance profile permissions. D creates an EC2 instance role trusting Amazon EC2 with AmazonSSMManagedInstanceCore attached, then uses a Config rule, ec2-instance-profile-attached, with the AWS-SetupManagedRoleOnEc2Instance document as remediation. Although the role and policy are appropriate, attaching the role through Config remediation is reactive, so the instance exists without the role until the rule evaluates; the requirement is that instances be managed automatically after creation. A is correct.

Community Comment Notes

Community voted A unanimously. Srikantha explained that by setting the default-ec2-instance-management-role service setting, new EC2 instances automatically assume the correct role, allowing seamless management by AWS Systems Manager. Ky_24 described the default instance management role being automatically attached to new EC2 instances upon creation. ArunRav made the decisive supporting observation that Amazon Linux already has the agent installed, so option A's remaining steps are what complete Systems Manager management. No alternative received support.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide