Use Systems Manager Patch Manager to find missing patches and automate remediation
A company uses Amazon EC2 Linux instances in the AWS Cloud. A member of the company’s security team recently received a report about common vulnerability identifiers on the instances. A security engineer needs to verify patching and perform remediation if the instances do not have the correct patches installed. The security engineer must determine which EC2 instances are at risk and must implement a solution to automatically update those instances with the applicable patches. What should the security engineer do to meet these requirements?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Patch Manager is the native SSM capability for viewing missing-patch vulnerability identifiers and automating patching. AWS Inspector (C/D) discovers vulnerabilities/CVEs but does not itself patch; AWS Shield Advanced (B) is DDoS protection, not patch scanning. Only A pairs 'view missing patches' and 'automate patching' correctly within SSM.
A security engineer must identify EC2 Linux instances missing patches (from reported CVEs) and automatically apply the correct patches. AWS Systems Manager Patch Manager scans managed instances for missing patches against a baseline and automates patch installation on a schedule, covering both the 'determine risk' and 'remediate' requirements in one service.
Assuming Inspector (C/D) patches—Inspector scans and reports CVEs but does not remediate; you still need Patch Manager/SSM to apply fixes. Using Shield Advanced (B) for vulnerability identification—Shield is for DDoS mitigation, unrelated to OS patching.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.