Create a Systems Manager State Manager association targeting all managed nodes to run the antivirus document

Answer Correct answer: A — create a State Manager association targeting all managed nodes that runs the antivirus Systems Manager document.

A DevOps engineer needs to implement a solution to install antivirus software on all the Amazon EC2 instances in an AWS account. The EC2 instances run the most recent version of Amazon Linux. The solution must detect all instances and must use an AWS Systems Manager document to install the software if the software is not present. Which solution will meet these requirements?

  1. Create an association in Systems Manager State Manager. Target all the managed nodes. Include the software in the association. Configure the association to use the Systems Manager document. Correct Answer
  2. Set up AWS Config to record all the resources in the account. Create an AWS Config custom rule to determine if the software is installed on all the EC2 instances. Configure an automatic remediation action that uses the Systems Manager document for noncompliant EC2 instances.
  3. Activate Amazon EC2 scanning on Amazon Inspector to determine if the software is installed on all the EC2 instances. Associate the findings with the Systems Manager document.
  4. Create an Amazon EventBridge rule that uses AWS CloudTrail to detect the Runinstances API call. Configure inventory collection in Systems Manager Inventory to determine if the software is installed on the EC2 instances. Associate the Systems Manager inventory with the Systems Manager document.

Community Votes

A
80%
B
20%

80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

State Manager associations are the mechanism for declaring desired state across a set of managed nodes and continuously enforcing it with an SSM document, which matches both the detection and installation requirements in one step (A). Option B splits the requirement into AWS Config for detection plus remediation, adding a second service and a custom rule for something State Manager already does. Option C misuses Inspector, which scans for package vulnerabilities and cannot install software or be associated with an SSM document. Option D relies on CloudTrail plus Inventory, which does not provide an install action.

Antivirus must be installed on every EC2 instance in the account using a Systems Manager document, with detection of all instances. A State Manager association targeting all managed nodes and referencing the Systems Manager document applies the desired state continuously, so instances that are missing the software are detected and remediated automatically, and drift such as a new instance or an uninstall is corrected on the next association execution.

Creating an AWS Config custom rule with an automatic remediation using the SSM document (B) — while this combines detection and remediation, Config adds a second configuration-recording and rule-evaluation layer plus a custom rule to maintain, whereas State Manager expresses the same intent natively; limelight04 preferred B but it is the less direct mechanism. Activating Amazon EC2 scanning in Amazon Inspector (C) — Inspector identifies vulnerabilities and package inventory, it cannot install software, and findings cannot be associated with an SSM document to perform installation.

Community Discussion (6 comments)

spring21 👍 1 Selected: A
https://docs.aws.amazon.com/systems-manager/latest/userguide/state-manager-associations-creating.html
limelight04 👍 1 Selected: B
Given the requirement to detect instances and use an SSM document for installation, Option B seems most appropriate. It combines AWS Config for detection and Systems Manager for remediation.
jamesf 👍 1 Selected: A
AWS Systems Manager State Manager: Automatic Detection: - State Manager allows you to manage the desired state of your AWS resources, including EC2 instances. By targeting all managed nodes, you ensure that every EC2 instance under Systems Manager's management is included in the scope. Software Installation: - You can specify a Systems Manager document (SSM document) to define the steps required to install the antivirus software. The association will ensure that the software is installed on any instances where it is missing. Continuous Compliance: - State Manager can continuously enforce the desired state, which means it will periodically check for the presence of the software and reapply the document if necessary.
d0229a2 👍 1
State Manager associations A State Manager association is a configuration that you assign to your AWS resources. The configuration defines the state that you want to maintain on your resources. For example, an association can specify that antivirus software must be installed and running on a managed node, or that certain ports must be closed. An association specifies a schedule for when to apply the configuration and the targets for the association. For example, an association for antivirus software might run once a day on all managed nodes in an AWS account. If the software isn't installed on a node, then the association could instruct State Manager to install it. If the software is installed, but the service isn't running, then the association could instruct State Manager to start the service.
trungtd 👍 2 Selected: A
By creating an association, you can ensure that all instances have the antivirus software installed and kept up-to-date.
tgv 👍 1
---> I'm between A & D Not 100% sure about this but here are my 2 cents about DETECTING the instances that don't have the software installed: A - it's a bit tricky because it states that it targets all managed nodes - but what if there are other nodes that are not managed? It just assumes that all instances are managed by AWS Systems Manager B - How can Config determine if the software is installed? C - Amazon Inspector is focused on security assessments and compliance checks, not on ensuring software is installed. It would require additional setup and is not designed for direct software installation. D - it ensures that all instances are detected. It ensures that the installed software is tracked by using the AWS Systems Manager Inventory (which is designed for this kind of things). I'm not 100% sure about the phrase "Associate the Systems Manager inventory with the Systems Manager document." which I don't believe its technically possible

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS Systems Manager State Manager defines a desired state for a set of managed nodes and enforces it through an association. Creating an association that targets all managed nodes and includes the antivirus software together with the Systems Manager document achieves both halves of the requirement: because the association covers all managed nodes, every EC2 instance in the account is evaluated, and because it references the document, instances where the software is absent have it installed. The association is also corrective, so any instance that drifts out of compliance is brought back, which satisfies the detect-and-install requirement with a single mechanism.

Why the Other Options Are Wrong

B records resources with AWS Config, creates a custom rule to determine whether the software is installed, and configures automatic remediation with the SSM document. This can work, but it introduces a second service, a configuration recorder, and a custom rule whose logic must be written and maintained, all to accomplish what a single State Manager association does natively; limelight04's preference for B is understandable but it is the less direct design. C activates EC2 scanning in Amazon Inspector and associates findings with an SSM document. Inspector scans for vulnerabilities and software inventory, cannot install software, and its findings cannot be wired to a document as an installation action. D creates an EventBridge rule on CloudTrail RunInstances events and combines Systems Manager Inventory with an SSM document, which provides no mechanism to install the software and depends on CloudTrail detection rather than continuous enforcement. A is the correct answer.

Community Comment Notes

Community voted A (80), with B a 20 percent minority. Commenters linked the State Manager associations documentation and described the association as maintaining the desired state across all managed nodes, keeping the antivirus installed and current. limelight04 argued B because it explicitly combines detection with the SSM document, but State Manager performs both without the extra Config rule.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide