Create one custom patch baseline combining the OS and custom repositories and run AWS-RunPatchBaseline

Answer Correct answer: A — create one custom patch baseline covering both the OS and custom repositories and run AWS-RunPatchBaseline.

A company that uses electronic patient health records runs a fleet of Amazon EC2 instances with an Amazon Linux operating system. The company must continuously ensure that the EC2 instances are running operating system patches and application patches that are in compliance with current privacy regulations. The company uses a custom repository to store application patches. A DevOps engineer needs to automate the deployment of operating system patches and application patches. The DevOps engineer wants to use both the default operating system patch repository and the custom patch repository. Which solution will meet these requirements with the LEAST effort?

  1. Use AWS Systems Manager to create a new custom patch baseline that includes the default operating system repository and the custom repository. Run the AWS-RunPatchBaseline document by using the Run command to verify and install patches. Use the BaselineOverride API to configure the new custom patch baseline. Correct Answer
  2. Use AWS Direct Connect to integrate the custom repository with the EC2 instances. Use Amazon EventBridge events to deploy the patches.
  3. Use the yum-config-manager command to add the custom repository to the /etc/yum.repos.d configuration. Run the yum-config-manager-enable command to activate the new repository.
  4. Use AWS Systems Manager to create a patch baseline for the default operating system repository and a second patch baseline for the custom repository. Run the AWS-RunPatchBaseline document by using the Run command to verify and install patches. Use the BaselineOverride API to configure the default patch baseline and the custom patch baseline.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The decisive constraint is that a patch baseline is the unit Patch Manager works with, and one baseline can reference multiple patch repositories, so combining both sources into a single custom baseline is what allows one automation run to patch both the OS and the application (A). phu0298 identified why the two-baseline alternative fails, that creating and managing two separate baselines increases complexity and that AWS-RunPatchBaseline operates against one baseline. f4b18ba noted that allowing a single custom baseline to include both the default OS repository and the custom repository centralizes the management rather than splitting it.

Both the default operating system patch repository and the company's custom application patch repository must be used together, and Patch Manager applies patches from exactly one patch baseline at a time. The correct approach is to create a single custom patch baseline that includes both the default operating system repository and the custom repository, and then run the AWS-RunPatchBaseline Systems Manager document through Run Command to verify and install the patches. Using the BaselineOverride API to configure that same combined baseline keeps the definition in one place.

Creating two separate patch baselines, one for the default OS repository and one for the custom repository, and configuring both with BaselineOverride (D) — as Srikantha and phu0298 explained, Systems Manager does not apply two baselines in a single run, so the second baseline would never be applied by the AWS-RunPatchBaseline invocation, and managing two baselines adds complexity rather than removing it. Using AWS Direct Connect to integrate the custom repository with the instances plus EventBridge to deploy patches (B) — Direct Connect is a private network link between an on-premises location and AWS and has no relationship to patch repository configuration, and EventBridge events do not perform the patching itself. Running yum-config-manager to add and enable the custom repository in /etc/yum.repos.d (C) — that makes the repository available to the OS package manager but automates nothing: there is no scheduled verification or installation of patches, so it does not meet the requirement to automate patch deployment.

Community Discussion (4 comments)

phu0298 👍 5
A Why Not Option D? Two Separate Patch Baselines: Creating and managing two separate patch baselines (one for OS patches and one for the custom repository) increases complexity. Running AWS-RunPatchBaseline twice (once for each baseline) adds unnecessary operational overhead.
Srikantha 👍 1 Selected: A
D. Systems Manager does not support using two separate patch baselines at once. You must define a single patch baseline that includes all patch sources.
Srikantha 👍 1 Selected: A
To automate patching while using both the default OS patch repo and a custom app patch repo, the most efficient and scalable solution is to: Use AWS Systems Manager Patch Manager, which supports: Custom patch baselines Combining default repositories with custom ones Centralized, automated patch management Create a custom patch baseline that: Includes the Amazon Linux OS patching rules Defines custom sources (your custom app patch repository) Use AWS-RunPatchBaseline SSM document to apply patches. Optionally, use the BaselineOverride parameter if you want to temporarily apply a different baseline (e.g., for testing).
f4b18ba 👍 4 Selected: A
AWS Systems Manager allows you to create a custom patch baseline that includes both the default operating system repository and the custom repository. This centralizes the management of patch baselines. The AWS-RunPatchBaseline document can be run using the Systems Manager Run Command to automate the verification and installation of patches, ensuring compliance with current privacy regulations. Using the BaselineOverride API provides flexibility to override the default settings with a custom patch baseline, streamlining the patching process across all EC2 instances.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement is to automate the deployment of both operating system patches and application patches, drawing on the default operating system patch repository and the company's custom application patch repository. AWS Systems Manager Patch Manager applies patches by evaluating a patch baseline, and a patch baseline is the unit that determines which patch groups are approved and which repositories they draw from; critically, a baseline can include more than one patch source, so a single custom baseline can reference both the default operating system repository and the custom repository (A). The AWS-RunPatchBaseline document, invoked through Systems Manager Run Command, then verifies and installs the patches for that baseline in a single automated run, and the BaselineOverride API configures that same combined baseline so its definition stays in one place (A). Because one baseline and one document cover both sources, this is the least-effort approach: it centralizes patch management rather than splitting it. f4b18ba described exactly this, that Systems Manager allows a single custom patch baseline to include both the default operating system repository and the custom repository, centralizing baseline management. A is the correct answer.

Why the Other Options Are Wrong

B uses AWS Direct Connect to integrate the custom repository with the EC2 instances and uses EventBridge events to deploy the patches. AWS Direct Connect establishes a private network connection between an on-premises data center and AWS; it has no function in configuring patch repositories or delivering patches to instances. EventBridge can trigger a workflow on a schedule, but it does not itself verify or install patches, so nothing in this option performs the patching. C uses the yum-config-manager command to add the custom repository to /etc/yum.repos.d and runs yum-config-manager-enable to activate it. This makes the custom repository known to the OS package manager, which is a prerequisite for installing application patches manually, but it automates nothing: there is no scheduled patch verification, no baseline, and no installation step, so the requirement to automate deployment of both OS and application patches is not met. D creates one patch baseline for the default operating system repository and a second patch baseline for the custom repository, runs AWS-RunPatchBaseline through Run Command, and configures both baselines with the BaselineOverride API. As Srikantha and phu0298 both explained, Systems Manager does not apply two separate patch baselines in a single run, so the second baseline covering the custom repository would never be applied by the AWS-RunPatchBaseline invocation, leaving the application patches unpatched; phu0298 added that creating and managing two separate baselines increases complexity, which is the opposite of least effort. A is correct.

Community Comment Notes

Community voted A unanimously. phu0298 directly addressed why option D is wrong, noting that two separate patch baselines increase complexity and that running AWS-RunPatchBaseline operates against a single baseline, so one of the two repositories would never be patched. Srikantha made the same point about Systems Manager not supporting two baselines at once and stated that a single patch baseline including all patch sources must be defined. f4b18ba supported A, explaining that Systems Manager permits one custom patch baseline to include both the default operating system repository and the custom repository, centralizing baseline management. No alternative received support.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide