Refactor user data to cfn-init with cfn-hup, and enforce the SSM document with a State Manager association

Answer Correct answer: B, E — refactor user data to cfn-init with cfn-hup, and use an SSM document with a State Manager association to apply changes to running instances.

A DevOps engineer has created an AWS CloudFormation template that deploys an application on Amazon EC2 instances. The EC2 instances run Amazon Linux. The application is deployed to the EC2 instances by using shell scripts that contain user data. The EC2 instances have an IAM instance profile that has an IAM role with the AmazonSSMManagedinstanceCore managed policy attached. The DevOps engineer has modified the user data in the CloudFormation template to install a new version of the application. The engineer has also applied the stack update. However, the application was not updated on the running EC2 instances. The engineer needs to ensure that the changes to the application are installed on the running EC2 instances. Which combination of steps will meet these requirements? (Choose two.)

  1. Configure the user data content to use the Multipurpose Internet Mail Extensions (MIME) multipart format. Set the scripts-user parameter to always in the text/cloud-config section.
  2. Refactor the user data commands to use the cfn-init helper script. Update the user data to install and configure the cfn-hup and cfn-init helper scripts to monitor and apply the metadata changes. Correct Answer
  3. Configure an EC2 launch template for the EC2 instances. Create a new EC2 Auto Scaling group. Associate the Auto Scaling group with the EC2 launch template. Use the AutoScalingScheduledAction update policy for the Auto Scaling group.
  4. Refactor the user data commands to use an AWS Systems Manager document (SSM document). Add an AWS CLI command in the user data to use Systems Manager Run Command to apply the SSM document to the EC2 instances.
  5. Refactor the user data command to use an AWS Systems Manager document (SSM document). Use Systems Manager State Manager to create an association between the SSM document and the EC2 instances. Correct Answer

Community Votes

BE
73%
BD
27%

73% of anonymous learners picked answer BE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

cfn-hup is a daemon that watches the instance metadata for changes and re-invokes cfn-init, which is exactly the mechanism for applying template updates to running instances (B). An SSM document combined with a State Manager association keeps re-applying the desired state automatically (E). Run Command from user data (D) fails because user data never re-runs, and an Auto Scaling scheduled action (C) replaces instances instead of updating the running ones.

User data only runs when an instance boots, so editing it in the CloudFormation template does not update already-running EC2 instances. Refactoring the user data to use the cfn-init helper plus the cfn-hup daemon lets CloudFormation detect metadata changes and re-run cfn-init on running instances. Complementarily, moving the logic into an SSM document and creating a State Manager association makes Systems Manager continuously enforce the document on the fleet, so the application version converges without manual steps.

Using Systems Manager Run Command invoked from user data (D)—user data executes only at instance launch, so it never reaches already-running instances, adding an unnecessary indirection. Using an Auto Scaling group scheduled action with a launch template (C)—that rotates instances rather than updating the application on the existing ones, which is not what the requirement asks. CloudFormation's own answer is cfn-init plus cfn-hup, optionally reinforced by State Manager.

Community Discussion (12 comments)

vortegon 👍 8 Selected: BE
B and E are the most effective in ensuring that updates to the application are installed on the running EC2 instances by leveraging CloudFormation's and AWS Systems Manager's capabilities for managing and applying updates.
Srikantha 👍 1 Selected: BE
The best combination of steps to ensure the application is updated on the running EC2 instances during a CloudFormation stack update is: B. Refactor the user data commands to use the cfn-init helper script. Update the user data to install and configure the cfn-hup and cfn-init helper scripts to monitor and apply the metadata changes. D. Refactor the user data commands to use an AWS Systems Manager document (SSM document). Add an AWS CLI command in the user data to use Systems Manager Run Command to apply the SSM document to the EC2 instances.
dkp 👍 3 Selected: BE
B&E D. Systems Manager Run Command (with user data): Using Run Command within user data to apply an SSM document introduces an unnecessary step. Option E with State Manager automates the process.
WhyIronMan 👍 2 Selected: BE
B, E. "Association" is the key. Details are everything during an Investigation...
Seoyong 👍 1 Selected: E
User data is executed when the system starts, not executed in runing EC2.
vmahilevskyi 👍 3 Selected: BE
EC2 instance profile with AmazonSSMManagedinstanceCore policy doesn't have permissions to SSM Run Command, so D is incorrect. So for me it's BE.
ogerber 👍 2 Selected: BE
"Add an AWS CLI command in the user data to use Systems Manager Run Command to apply the SSM document to the EC2 instances."
fdoxxx 👍 1
B and D A. This option is not applicable for updating applications on EC2 instances. B. Refactoring the user data commands to use the cfn-init helper script helps in handling metadata changes and applying them to the EC2 instances. This is especially useful in CloudFormation stack updates. C. Creating a new EC2 Auto Scaling group with an update policy doesn't necessarily address the application update requirement in this scenario. D. Refactoring the user data commands to use an AWS Systems Manager document and using Run Command to apply the SSM document is a valid approach for updating applications on EC2 instances. E. While using Systems Manager documents and State Manager is a valid approach, it might be more complex than needed for a straightforward update of an application on EC2 instances. Therefore, options B and D together provide a good solution for updating the application on the running EC2 instances.
Ramdi1 👍 1 Selected: BD
ption B: cfn-init is a powerful tool for managing configuration on EC2 instances. By using cfn-init, the DevOps engineer can ensure that the new application version is installed regardless of the current state of the instances Option D: SSM documents provide a centralized and reusable way to manage configurations. By using Run Command, the engineer can trigger the application update on all instances directly from the template.
thanhnv142 👍 2 Selected: BD
B and D: A: irrelevant B: cfn-init is perfectly correct for this purpose C: irrelevant. The question does not mention autoscaling group D: <Systems Manager Run Command > can help install packages, so it is correct E: < Systems Manager State Manager> is used to maintain, not to update
Ramdi1 👍 2 Selected: BD
Here's why these options are correct: Option B: cfn-init is a powerful tool for managing configuration on EC2 instances. By using cfn-init, the DevOps engineer can ensure that the new application version is installed regardless of the current state of the instances. cfn-hup helps keep cfn-init updated with the latest configuration changes. Option D: SSM documents provide a centralized and reusable way to manage configurations. By using Run Command, the engineer can trigger the application update on all instances directly from the template. This approach allows for easier management and updates in the future.
hotblooded 👍 2 Selected: BD
cfn-hup to chek for updates in cloudformation and ssm run command to run commands if required for application

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

EC2 user data is consumed only during instance bootstrap, so applying a stack update that changes user data does not re-run it on running instances. Refactoring the commands into the cfn-init helper and installing the cfn-hup daemon makes CloudFormation poll the instance metadata and automatically re-execute cfn-init when metadata changes, which applies the new application version in place. Independently, defining the work as an SSM document and creating a State Manager association makes Systems Manager continuously enforce that document on the instances, guaranteeing convergence to the stable version.

Why the Other Options Are Wrong

C uses a launch template plus an Auto Scaling scheduled action, which terminates and replaces instances rather than updating the application on the existing running instances, so it does not meet the stated requirement. D invokes Systems Manager Run Command from user data, but because user data runs only at launch, that command never executes on instances that are already running. A is about MIME multipart formatting, which changes how user data is delivered but does not make it re-run. B and E are the correct pair.

Community Comment Notes

Community voted B,E (70), with B,D a minority (26). Commenters emphasized that cfn-hup plus cfn-init applies metadata changes to running instances and that a State Manager association automates ongoing enforcement, whereas Run Command from user data adds an unnecessary step and manual effort.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide