Create one custom patch baseline combining the OS and custom repositories and run AWS-RunPatchBaseline
A company that uses electronic patient health records runs a fleet of Amazon EC2 instances with an Amazon Linux operating system. The company must continuously ensure that the EC2 instances are running operating system patches and application patches that are in compliance with current privacy regulations. The company uses a custom repository to store application patches. A DevOps engineer needs to automate the deployment of operating system patches and application patches. The DevOps engineer wants to use both the default operating system patch repository and the custom patch repository. Which solution will meet these requirements with the LEAST effort?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The decisive constraint is that a patch baseline is the unit Patch Manager works with, and one baseline can reference multiple patch repositories, so combining both sources into a single custom baseline is what allows one automation run to patch both the OS and the application (A). phu0298 identified why the two-baseline alternative fails, that creating and managing two separate baselines increases complexity and that AWS-RunPatchBaseline operates against one baseline. f4b18ba noted that allowing a single custom baseline to include both the default OS repository and the custom repository centralizes the management rather than splitting it.
Both the default operating system patch repository and the company's custom application patch repository must be used together, and Patch Manager applies patches from exactly one patch baseline at a time. The correct approach is to create a single custom patch baseline that includes both the default operating system repository and the custom repository, and then run the AWS-RunPatchBaseline Systems Manager document through Run Command to verify and install the patches. Using the BaselineOverride API to configure that same combined baseline keeps the definition in one place.
Creating two separate patch baselines, one for the default OS repository and one for the custom repository, and configuring both with BaselineOverride (D) — as Srikantha and phu0298 explained, Systems Manager does not apply two baselines in a single run, so the second baseline would never be applied by the AWS-RunPatchBaseline invocation, and managing two baselines adds complexity rather than removing it. Using AWS Direct Connect to integrate the custom repository with the instances plus EventBridge to deploy patches (B) — Direct Connect is a private network link between an on-premises location and AWS and has no relationship to patch repository configuration, and EventBridge events do not perform the patching itself. Running yum-config-manager to add and enable the custom repository in /etc/yum.repos.d (C) — that makes the repository available to the OS package manager but automates nothing: there is no scheduled verification or installation of patches, so it does not meet the requirement to automate patch deployment.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement is to automate the deployment of both operating system patches and application patches, drawing on the default operating system patch repository and the company's custom application patch repository. AWS Systems Manager Patch Manager applies patches by evaluating a patch baseline, and a patch baseline is the unit that determines which patch groups are approved and which repositories they draw from; critically, a baseline can include more than one patch source, so a single custom baseline can reference both the default operating system repository and the custom repository (A). The AWS-RunPatchBaseline document, invoked through Systems Manager Run Command, then verifies and installs the patches for that baseline in a single automated run, and the BaselineOverride API configures that same combined baseline so its definition stays in one place (A). Because one baseline and one document cover both sources, this is the least-effort approach: it centralizes patch management rather than splitting it. f4b18ba described exactly this, that Systems Manager allows a single custom patch baseline to include both the default operating system repository and the custom repository, centralizing baseline management. A is the correct answer.Why the Other Options Are Wrong
B uses AWS Direct Connect to integrate the custom repository with the EC2 instances and uses EventBridge events to deploy the patches. AWS Direct Connect establishes a private network connection between an on-premises data center and AWS; it has no function in configuring patch repositories or delivering patches to instances. EventBridge can trigger a workflow on a schedule, but it does not itself verify or install patches, so nothing in this option performs the patching. C uses the yum-config-manager command to add the custom repository to /etc/yum.repos.d and runs yum-config-manager-enable to activate it. This makes the custom repository known to the OS package manager, which is a prerequisite for installing application patches manually, but it automates nothing: there is no scheduled patch verification, no baseline, and no installation step, so the requirement to automate deployment of both OS and application patches is not met. D creates one patch baseline for the default operating system repository and a second patch baseline for the custom repository, runs AWS-RunPatchBaseline through Run Command, and configures both baselines with the BaselineOverride API. As Srikantha and phu0298 both explained, Systems Manager does not apply two separate patch baselines in a single run, so the second baseline covering the custom repository would never be applied by the AWS-RunPatchBaseline invocation, leaving the application patches unpatched; phu0298 added that creating and managing two separate baselines increases complexity, which is the opposite of least effort. A is correct.Community Comment Notes
Community voted A unanimously. phu0298 directly addressed why option D is wrong, noting that two separate patch baselines increase complexity and that running AWS-RunPatchBaseline operates against a single baseline, so one of the two repositories would never be patched. Srikantha made the same point about Systems Manager not supporting two baselines at once and stated that a single patch baseline including all patch sources must be defined. f4b18ba supported A, explaining that Systems Manager permits one custom patch baseline to include both the default operating system repository and the custom repository, centralizing baseline management. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →