Set the Systems Manager default EC2 instance management role so new instances are managed automatically
A company uses AWS Systems Manager to manage a fleet of Amazon Linux EC2 instances that have SSM Agent installed. All EC2 instances are configured to use Instance Metadata Service Version 2 (IMDSv2) and are running in the same AWS account and AWS Region. Company policy requires developers to use only Amazon Linux. The company wants to ensure that all new EC2 instances are automatically managed by Systems Manager after creation. Which solution will meet these requirements with the MOST operational efficiency?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The requirement is that new instances become managed automatically after creation, which calls for an account-level default rather than a reactive check (A). The Systems Manager default-ec2-instance-management-role service setting is applied automatically to EC2 instances at creation, so instances never need a manual step or a Config remediation to gain the role (A). Options B, C, and D all depend on AWS Config evaluating, Patch Manager running, or an EventBridge schedule firing after the fact, so instances exist unmanaged for a period of time, which is the opposite of the automatic-at-creation requirement.
Every instance runs Amazon Linux with SSM Agent already installed and uses IMDSv2, so the only thing a new instance needs in order to be managed by Systems Manager is an IAM instance profile granting the Systems Manager permissions. Systems Manager supports a default EC2 instance management role that is automatically attached to newly created EC2 instances, so creating a role whose trust policy allows Systems Manager to assume it, attaching the AmazonSSMManagedEC2InstanceDefaultPolicy managed policy, and configuring the default-ec2-instance-management-role service setting to that role makes every new instance managed on creation with no per-instance action.
Using an AWS Config rule that validates whether SSM Agent is installed with remediation running AWS-InstallSSMAgent (B) — this installs the agent reactively after a Config evaluation, so a newly created instance is unmanaged until the rule runs and remediation completes, and the agent is already present here so installing it is not the gap. Using Patch Manager with a patch baseline, patch group, and daily maintenance window to install SSM Agent (C) — a maintenance window runs on a daily schedule, so a new instance could be unmanaged for up to a day, and installing the agent is again not the requirement. Using a Config rule with the ec2-instance-profile-attached rule and AWS-SetupManagedRoleOnEc2Instance remediation (D) — this attaches the role reactively after a Config evaluation rather than automatically at creation, so it does not meet the automatic requirement.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The fleet consists of Amazon Linux instances that already have SSM Agent installed and use IMDSv2, so the only remaining requirement for Systems Manager management is an IAM instance profile whose permissions allow Systems Manager to manage the instance. AWS Systems Manager provides a default EC2 instance management role that is attached automatically to EC2 instances when they are created, and an administrator configures it by creating an IAM role whose trust policy allows Systems Manager to assume it, attaching the AmazonSSMManagedEC2InstanceDefaultPolicy managed policy to that role, and then setting the default-ec2-instance-management-role Systems Manager service setting to that role (A). Once configured, every instance created afterward receives the role automatically and is managed by Systems Manager from the moment it comes up, with no per-instance action, no scheduled evaluation, and no remediation run. Ky_24 explained exactly this automatic role association, and Srikantha noted that setting the default-ec2-instance-management-role service setting means new instances automatically assume the correct role for seamless Systems Manager management. A is the correct answer.Why the Other Options Are Wrong
B ensures AWS Config is set up, creates a Config rule validating that an EC2 instance has SSM Agent installed, runs it on configuration changes, and configures automatic remediation running AWS-InstallSSMAgent. Two problems exist. The agent is already installed on these Amazon Linux instances, so validating and installing it addresses nothing; the actual gap is the instance profile. And because the mechanism is a Config rule with remediation, it is reactive: a newly created instance is unmanaged until the configuration change is evaluated and remediation runs, which fails the requirement that instances be managed automatically after creation. C configures Systems Manager Patch Manager with a patch baseline, a patch group for all instances, and a maintenance window with a task that installs SSM Agent daily. A daily maintenance window means a newly created instance could remain unmanaged for up to a day, and Patch Manager is a patching mechanism rather than a mechanism for granting instance profile permissions. D creates an EC2 instance role trusting Amazon EC2 with AmazonSSMManagedInstanceCore attached, then uses a Config rule, ec2-instance-profile-attached, with the AWS-SetupManagedRoleOnEc2Instance document as remediation. Although the role and policy are appropriate, attaching the role through Config remediation is reactive, so the instance exists without the role until the rule evaluates; the requirement is that instances be managed automatically after creation. A is correct.Community Comment Notes
Community voted A unanimously. Srikantha explained that by setting the default-ec2-instance-management-role service setting, new EC2 instances automatically assume the correct role, allowing seamless management by AWS Systems Manager. Ky_24 described the default instance management role being automatically attached to new EC2 instances upon creation. ArunRav made the decisive supporting observation that Amazon Linux already has the agent installed, so option A's remaining steps are what complete Systems Manager management. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →