AnswerCorrect answer: C — an AWS Config required-applications rule plus EventBridge to Lambda and SSM Run Command detects and auto-installs the package.
A company has AWS accounts in an organization in AWS Organizations. The company needs to install a corporate software package on all Amazon EC2 instances for all the accounts in the organization. A central account provides base AMIs for the EC2 instances. The company uses AWS Systems Manager for software inventory and patching operations. A security engineer must implement a solution that detects EC2 instances that do not have the required software. The solution also must automatically install the software if the software is not present. Which solution will meet these requirements?
Provide new AMIs that have the required software pre-installed. Apply a tag to the AMIs to indicate that the AMIs have the required software. Configure an SCP that allows new EC2 instances to be launched only if the instances have the tagged AMIs. Tag all existing EC2 instances.
Configure a custom patch baseline in Systems Manager Patch Manager. Add the package name for the required software to the approved packages list. Associate the new patch baseline with all EC2 instances. Set up a maintenance window for software deployment.
Centrally enable AWS Config. Set up the ec2-managedinstance-applications-required AWS Config rule for all accounts. Create an Amazon EventBridge rule that reacts to AWS Config events. Configure the EventBridge rule to invoke an AWS Lambda function that uses Systems Manager Run Command to install the required software. Correct Answer
Create a new Systems Manager Distributor package for the required software. Specify the download location. Select all EC2 instances in the different accounts. Install the software by using Systems Manager Run Command.
Community Votes
C
100%
100% of anonymous learners picked answer C.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The ec2-managedinstance-applications-required Config rule continuously evaluates whether managed instances have the required applications, emitting compliance-state changes that EventBridge can route to a Lambda. Using SSM Run Command from that Lambda installs the software on demand, fulfilling both detection and automatic installation without manual per-account work.
The company must find EC2 instances lacking a required corporate package and install it automatically. Centrally enabling AWS Config with the ec2-managedinstance-applications-required rule flags non-compliant instances; an EventBridge rule reacts to the Config compliance-change event and invokes a Lambda function that uses Systems Manager Run Command to install the package. This both detects and remediates across all organization accounts.
Using a patch baseline (Patch Manager) for a corporate application—patch baselines handle OS security/bugfix patches, not arbitrary software packages. Or using SSM Distributor alone, which installs packages but does not detect missing ones.
Community Discussion (8 comments)
phmeeeee👍 1Selected: C
A - SCP is restriction not configuration. B - Patch Baseline is for OS-level patches not software packages. D - This is for manual software installation C - Can install software packages based on event from AWS Config and send in to EventBridge to trigger the function.
navid1365👍 3Selected: C
C: This solution uses AWS Config to monitor the compliance of EC2 instances with the required software. AWS Config can detect instances that do not have the software installed and trigger an automated remediation process using AWS Lambda and Systems Manager Run Command.
kupo777👍 3
C is correct. Option A is a method of restricting activation by tag without detection. Option B is Software cannot be installed. Option D is to install the software without detection.
aescudero51👍 4Selected: C
My answer is C. Detecting Missing Software: AWS Config with the ec2-managedinstance-applications-required rule continuously monitors EC2 instances and identifies ones without the required software. Automated Installation: The EventBridge rule automatically triggers upon a Config non-compliance event. Centralized Management: The solution operates centrally from the organization's master account, ensuring consistent enforcement across all member accounts. Flexibility: This approach allows for future software updates by simply modifying the Lambda function logic or the package definition in Systems Manager Distributor.
Mandar👍 1
D is correct: https://docs.aws.amazon.com/systems-manager/latest/userguide/distributor.html
aescudero51👍 4Selected: C
C is correct https://aws.amazon.com/blogs/mt/deploying-packages-sequentially-aws-systems-manager/
Shreyas👍 1Selected: B
Ans - B
Viseks👍 2
Ans - B
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
AWS Config's ec2-managedinstance-applications-required rule detects instances that do not have the required application installed. An EventBridge rule keyed on the Config compliance-change event invokes a Lambda function that runs Systems Manager Run Command to install the package, giving automatic remediation centrally. This meets both the detection and auto-install requirements across all accounts.
Why the Other Options Are Wrong
A uses an SCP to restrict launches to tagged AMIs, which enforces future launches but does not detect or fix existing instances. B (patch baseline) manages OS patches, not a custom corporate software package, and does not detect missing installs. D (Distributor) can push the package but does not detect which instances lack it, failing the detection requirement.
Community Comment Notes
Community favored C (92 votes). Commenters noted A is restriction-only, B is for OS patches not software, and D installs without detection; C both detects via Config and remediates via EventBridge/Lambda/Run Command. One D vote linked Distributor but missed the detection gap.