Refactor user data to cfn-init with cfn-hup, and enforce the SSM document with a State Manager association
A DevOps engineer has created an AWS CloudFormation template that deploys an application on Amazon EC2 instances. The EC2 instances run Amazon Linux. The application is deployed to the EC2 instances by using shell scripts that contain user data. The EC2 instances have an IAM instance profile that has an IAM role with the AmazonSSMManagedinstanceCore managed policy attached. The DevOps engineer has modified the user data in the CloudFormation template to install a new version of the application. The engineer has also applied the stack update. However, the application was not updated on the running EC2 instances. The engineer needs to ensure that the changes to the application are installed on the running EC2 instances. Which combination of steps will meet these requirements? (Choose two.)
Community Votes
73% of anonymous learners picked answer BE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
cfn-hup is a daemon that watches the instance metadata for changes and re-invokes cfn-init, which is exactly the mechanism for applying template updates to running instances (B). An SSM document combined with a State Manager association keeps re-applying the desired state automatically (E). Run Command from user data (D) fails because user data never re-runs, and an Auto Scaling scheduled action (C) replaces instances instead of updating the running ones.
User data only runs when an instance boots, so editing it in the CloudFormation template does not update already-running EC2 instances. Refactoring the user data to use the cfn-init helper plus the cfn-hup daemon lets CloudFormation detect metadata changes and re-run cfn-init on running instances. Complementarily, moving the logic into an SSM document and creating a State Manager association makes Systems Manager continuously enforce the document on the fleet, so the application version converges without manual steps.
Using Systems Manager Run Command invoked from user data (D)—user data executes only at instance launch, so it never reaches already-running instances, adding an unnecessary indirection. Using an Auto Scaling group scheduled action with a launch template (C)—that rotates instances rather than updating the application on the existing ones, which is not what the requirement asks. CloudFormation's own answer is cfn-init plus cfn-hup, optionally reinforced by State Manager.
Community Discussion (12 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
EC2 user data is consumed only during instance bootstrap, so applying a stack update that changes user data does not re-run it on running instances. Refactoring the commands into the cfn-init helper and installing the cfn-hup daemon makes CloudFormation poll the instance metadata and automatically re-execute cfn-init when metadata changes, which applies the new application version in place. Independently, defining the work as an SSM document and creating a State Manager association makes Systems Manager continuously enforce that document on the instances, guaranteeing convergence to the stable version.Why the Other Options Are Wrong
C uses a launch template plus an Auto Scaling scheduled action, which terminates and replaces instances rather than updating the application on the existing running instances, so it does not meet the stated requirement. D invokes Systems Manager Run Command from user data, but because user data runs only at launch, that command never executes on instances that are already running. A is about MIME multipart formatting, which changes how user data is delivered but does not make it re-run. B and E are the correct pair.Community Comment Notes
Community voted B,E (70), with B,D a minority (26). Commenters emphasized that cfn-hup plus cfn-init applies metadata changes to running instances and that a State Manager association automates ongoing enforcement, whereas Run Command from user data adds an unnecessary step and manual effort.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →