Use Systems Manager Patch Manager to find missing patches and automate remediation

Implement a secure and consistent deployment strategy for cloud resources.
Answer Correct answer: A — Systems Manager Patch Manager views missing patches and automates their installation on EC2 Linux instances.

A company uses Amazon EC2 Linux instances in the AWS Cloud. A member of the company’s security team recently received a report about common vulnerability identifiers on the instances. A security engineer needs to verify patching and perform remediation if the instances do not have the correct patches installed. The security engineer must determine which EC2 instances are at risk and must implement a solution to automatically update those instances with the applicable patches. What should the security engineer do to meet these requirements?

  1. Use AWS Systems Manager Patch Manager to view vulnerability identifiers for missing patches on the instances. Use Patch Manager also to automate the patching process. Correct Answer
  2. Use AWS Shield Advanced to view vulnerability identifiers for missing patches on the instances. Use AWS Systems Manager Patch Manager to automate the patching process.
  3. Use Amazon GuardDuty to view vulnerability identifiers for missing patches on the instances. Use Amazon inspector to automate the patching process.
  4. Use Amazon inspector to view vulnerability identifiers for missing patches on the instances. Use Amazon Inspector also to automate the patching process.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Patch Manager is the native SSM capability for viewing missing-patch vulnerability identifiers and automating patching. AWS Inspector (C/D) discovers vulnerabilities/CVEs but does not itself patch; AWS Shield Advanced (B) is DDoS protection, not patch scanning. Only A pairs 'view missing patches' and 'automate patching' correctly within SSM.

A security engineer must identify EC2 Linux instances missing patches (from reported CVEs) and automatically apply the correct patches. AWS Systems Manager Patch Manager scans managed instances for missing patches against a baseline and automates patch installation on a schedule, covering both the 'determine risk' and 'remediate' requirements in one service.

Assuming Inspector (C/D) patches—Inspector scans and reports CVEs but does not remediate; you still need Patch Manager/SSM to apply fixes. Using Shield Advanced (B) for vulnerability identification—Shield is for DDoS mitigation, unrelated to OS patching.

Community Discussion (5 comments)

phmeeeee 👍 1 Selected: A
This may tricky cuz vulnerability scanning is AWS Inspector, but for missing patch and patching automation is for Patch Manager.
navid1365 👍 2 Selected: A
AWS Systems Manager is the correct answer (A)
Certified101 👍 3 Selected: A
A agree
Nash101 👍 1
A -Agree
Zek 👍 2
A - Agree

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS Systems Manager Patch Manager both reports which instances are missing patches (against a patch baseline) and automatically installs the applicable patches on a schedule, fulfilling the 'determine risk' and 'remediate' requirements with a single managed service.

Why the Other Options Are Wrong

B pairs Shield Advanced (DDoS protection, irrelevant to OS patching) with Patch Manager, so the identification half is wrong. C and D assign vulnerability viewing to GuardDuty or Inspector; GuardDuty is threat detection, not patch scanning, and Inspector reports CVEs but does not apply patches. A is the complete correct pairing.

Community Comment Notes

Community voted A (100). Commenters stressed the trick: vulnerability scanning is Inspector, but missing-patch identification and patching automation is Patch Manager. A was agreed as correct.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide