Create a Systems Manager State Manager association targeting all managed nodes to run the antivirus document
A DevOps engineer needs to implement a solution to install antivirus software on all the Amazon EC2 instances in an AWS account. The EC2 instances run the most recent version of Amazon Linux. The solution must detect all instances and must use an AWS Systems Manager document to install the software if the software is not present. Which solution will meet these requirements?
Community Votes
80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
State Manager associations are the mechanism for declaring desired state across a set of managed nodes and continuously enforcing it with an SSM document, which matches both the detection and installation requirements in one step (A). Option B splits the requirement into AWS Config for detection plus remediation, adding a second service and a custom rule for something State Manager already does. Option C misuses Inspector, which scans for package vulnerabilities and cannot install software or be associated with an SSM document. Option D relies on CloudTrail plus Inventory, which does not provide an install action.
Antivirus must be installed on every EC2 instance in the account using a Systems Manager document, with detection of all instances. A State Manager association targeting all managed nodes and referencing the Systems Manager document applies the desired state continuously, so instances that are missing the software are detected and remediated automatically, and drift such as a new instance or an uninstall is corrected on the next association execution.
Creating an AWS Config custom rule with an automatic remediation using the SSM document (B) — while this combines detection and remediation, Config adds a second configuration-recording and rule-evaluation layer plus a custom rule to maintain, whereas State Manager expresses the same intent natively; limelight04 preferred B but it is the less direct mechanism. Activating Amazon EC2 scanning in Amazon Inspector (C) — Inspector identifies vulnerabilities and package inventory, it cannot install software, and findings cannot be associated with an SSM document to perform installation.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
AWS Systems Manager State Manager defines a desired state for a set of managed nodes and enforces it through an association. Creating an association that targets all managed nodes and includes the antivirus software together with the Systems Manager document achieves both halves of the requirement: because the association covers all managed nodes, every EC2 instance in the account is evaluated, and because it references the document, instances where the software is absent have it installed. The association is also corrective, so any instance that drifts out of compliance is brought back, which satisfies the detect-and-install requirement with a single mechanism.Why the Other Options Are Wrong
B records resources with AWS Config, creates a custom rule to determine whether the software is installed, and configures automatic remediation with the SSM document. This can work, but it introduces a second service, a configuration recorder, and a custom rule whose logic must be written and maintained, all to accomplish what a single State Manager association does natively; limelight04's preference for B is understandable but it is the less direct design. C activates EC2 scanning in Amazon Inspector and associates findings with an SSM document. Inspector scans for vulnerabilities and software inventory, cannot install software, and its findings cannot be wired to a document as an installation action. D creates an EventBridge rule on CloudTrail RunInstances events and combines Systems Manager Inventory with an SSM document, which provides no mechanism to install the software and depends on CloudTrail detection rather than continuous enforcement. A is the correct answer.Community Comment Notes
Community voted A (80), with B a 20 percent minority. Commenters linked the State Manager associations documentation and described the association as maintaining the desired state across all managed nodes, keeping the antivirus installed and current. limelight04 argued B because it explicitly combines detection with the SSM document, but State Manager performs both without the extra Config rule.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →