Register an imported EC2 instance with Systems Manager using the agent and an IAM role

Answer Correct answers: A, B — Verify that the Systems Manager agent is installed and running and that the instance has an appropriate IAM role for Systems Manager.

A solutions architect is importing a VM from an on-premises environment by using the Amazon EC2 VM Import feature of AWS Import/Export. The solutions architect has created an AMI and has provisioned an Amazon EC2 instance that is based on that AMI. The EC2 instance runs inside a public subnet in a VPC and has a public IP address assigned. The EC2 instance does not appear as a managed instance in the AWS Systems Manager console. Which combination of steps should the solutions architect take to troubleshoot this issue? (Choose two.)

  1. Verify that Systems Manager Agent is installed on the instance and is running. Correct Answer
  2. Verify that the instance is assigned an appropriate IAM role for Systems Manager. Correct Answer
  3. Verify the existence of a VPC endpoint on the VPC.
  4. Verity that the AWS Application Discovery Agent is configured.
  5. Verify the correct configuration of service-linked roles for Systems Manager.

Community Votes

AB
100%

100% of anonymous learners picked answer AB. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Systems Manager management requires two things on the instance: the SSM Agent running so the instance can register, and an IAM instance profile whose role grants the Systems Manager API permissions, because without the role the agent has no identity to call Systems Manager with.

A VM imported from on-premises with EC2 VM Import runs from a new AMI in a public subnet with a public IP address, but it does not appear as a managed instance in the AWS Systems Manager console. The architect must troubleshoot why Systems Manager is not managing it.

Looking for a VPC endpoint. The instance already has a public IP address in a public subnet and reaches Systems Manager over the internet, so interface endpoints for Systems Manager are not required and their absence is not the cause. Application Discovery Agent is a separate discovery tool and has no bearing on Systems Manager registration.

Community Discussion (5 comments)

ebbff63 👍 9
Answer:AB SSM Agent - must for communication between EC2 instances and Systems Manager Appropriate IAM role allows the instance to interact with Systems Manager services
AzureDP900 👍 1
A & B are right options. The EC2 instance not appearing as a managed instance in the AWS Systems Manager console suggests that the Systems Manager Agent is not running or is not properly configured. By verifying that the Systems Manager Agent is installed and running on the instance, the solutions architect can ensure that the agent is collecting metrics and data from the instance. Assigning an appropriate IAM role to the instance for Systems Manager ensures that the agent has the necessary permissions to collect data and perform management tasks.
Chungies 👍 1
I will go with A and B because with SSM agent it has to be installed on the VM and there has to be a role for it that allows it to interact with systems manager
Daniel76 👍 2 Selected: AB
https://docs.aws.amazon.com/systems-manager/latest/userguide/setup-instance-permissions.html
G4Exams 👍 1 Selected: AB
I also go for A and B. A, the agent for sure and I think B because without the role it would definitly have no access to that instance. I don't know why D should be related to the scenario.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

For an instance to appear as a managed instance in Systems Manager, the SSM Agent must be installed and running so it can register with the service, which is why A is correct. The agent also needs an identity, so the instance must be assigned an IAM role for Systems Manager whose trust relationship and permissions allow the agent to call Systems Manager APIs such as RegisterManagedInstance and to receive commands, which is why B is correct. AWS documents this as the instance permissions requirement, and a missing or incorrect role is the most common reason an instance never appears. Because the imported instance came from an on-premises image, it is entirely possible the original image had neither the agent nor a matching role configured, so both checks are the right starting point.

Why the Other Options Are Wrong

C: The instance runs in a public subnet and already has a public IP address, so it can reach the Systems Manager public endpoint over the internet without a VPC endpoint. A missing VPC endpoint is only relevant for a private subnet with no outbound path. D: The AWS Application Discovery Agent is used by Application Discovery Service and Migration Hub to inventory and map dependencies, and it has no role in Systems Manager registration, so configuring it would not make the instance appear. E: Service-linked roles are created automatically by AWS services on first use and are not something an architect verifies on an instance, so this is not a per-instance troubleshooting step.

Community Comment Notes

The community voted 100 to 0 for A and B, and the top-voted comment stated the two reasons directly, the Systems Manager agent is required for communication between the instance and Systems Manager, and the appropriate IAM role lets the instance interact with Systems Manager services. Commenters linked the AWS Systems Manager documentation on setting up instance permissions and one explicitly asked why the Application Discovery Agent should be relevant at all, which is consistent with it not being involved in this registration path.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide