Register an imported EC2 instance with Systems Manager using the agent and an IAM role
A solutions architect is importing a VM from an on-premises environment by using the Amazon EC2 VM Import feature of AWS Import/Export. The solutions architect has created an AMI and has provisioned an Amazon EC2 instance that is based on that AMI. The EC2 instance runs inside a public subnet in a VPC and has a public IP address assigned. The EC2 instance does not appear as a managed instance in the AWS Systems Manager console. Which combination of steps should the solutions architect take to troubleshoot this issue? (Choose two.)
Community Votes
100% of anonymous learners picked answer AB. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Systems Manager management requires two things on the instance: the SSM Agent running so the instance can register, and an IAM instance profile whose role grants the Systems Manager API permissions, because without the role the agent has no identity to call Systems Manager with.
A VM imported from on-premises with EC2 VM Import runs from a new AMI in a public subnet with a public IP address, but it does not appear as a managed instance in the AWS Systems Manager console. The architect must troubleshoot why Systems Manager is not managing it.
Looking for a VPC endpoint. The instance already has a public IP address in a public subnet and reaches Systems Manager over the internet, so interface endpoints for Systems Manager are not required and their absence is not the cause. Application Discovery Agent is a separate discovery tool and has no bearing on Systems Manager registration.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
For an instance to appear as a managed instance in Systems Manager, the SSM Agent must be installed and running so it can register with the service, which is why A is correct. The agent also needs an identity, so the instance must be assigned an IAM role for Systems Manager whose trust relationship and permissions allow the agent to call Systems Manager APIs such as RegisterManagedInstance and to receive commands, which is why B is correct. AWS documents this as the instance permissions requirement, and a missing or incorrect role is the most common reason an instance never appears. Because the imported instance came from an on-premises image, it is entirely possible the original image had neither the agent nor a matching role configured, so both checks are the right starting point.Why the Other Options Are Wrong
C: The instance runs in a public subnet and already has a public IP address, so it can reach the Systems Manager public endpoint over the internet without a VPC endpoint. A missing VPC endpoint is only relevant for a private subnet with no outbound path. D: The AWS Application Discovery Agent is used by Application Discovery Service and Migration Hub to inventory and map dependencies, and it has no role in Systems Manager registration, so configuring it would not make the instance appear. E: Service-linked roles are created automatically by AWS services on first use and are not something an architect verifies on an instance, so this is not a per-instance troubleshooting step.Community Comment Notes
The community voted 100 to 0 for A and B, and the top-voted comment stated the two reasons directly, the Systems Manager agent is required for communication between the instance and Systems Manager, and the appropriate IAM role lets the instance interact with Systems Manager services. Commenters linked the AWS Systems Manager documentation on setting up instance permissions and one explicitly asked why the Application Discovery Agent should be relevant at all, which is consistent with it not being involved in this registration path.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →