Deploy security patches immediately with a 0-day baseline and Patch Now, logging to S3 for evidence
Implement a secure and consistent deployment strategy for cloud resources.Design and implement an incident response plan.
AnswerCorrect answer: A, B — set a 0-day Security-class baseline as the AL2 default and use Patch Now (scan+install) with S3 log storage for immediate, evidenced patching.
An online media company has an application that customers use to watch events around the world. The application is hosted on a fleet of Amazon EC2 instances that run Amazon Linux 2. The company uses AWS Systems Manager to manage the EC2 instances. The company applies patches and application updates by using the AWS-AmazonLinux2DefaultPatchBaseline patching baseline in Systems Manager Patch Manager. The company is concerned about potential attacks on the application during the week of an upcoming event. The company needs a solution that can immediately deploy patches to all the EC2 instances in response to a security incident or vulnerability. The solution also must provide centralized evidence that the patches were applied successfully. Which combination of steps will meet these requirements? (Choose two.)
Create a new patching baseline in Patch Manager. Specify Amazon Linux 2 as the product. Specify Security as the classification. Set the automatic approval for patches to 0 days. Ensure that the new patching baseline is the designated default for Amazon Linux 2. Correct Answer
Use the Patch Now option with the scan and install operation in the Patch Manager console to apply patches against the baseline to all nodes. Specify an Amazon S3 bucket as the patching log storage option. Correct Answer
Use the Clone function of Patch Manager to create a copy of the AWS-AmazonLmux2DefaultPatchBaseline built-in baseline. Set the automatic approval for patches to 1 day.
Create a patch policy that patches all managed nodes and sends a patch operation log output to an Amazon S3 bucket. Use a custom scan schedule to set Patch Manager to check every hour for new patches. Assign the baseline to the patch policy.
Use Systems Manager Application Manager to inspect the package versions that were installed on the EC2 instances. Additionally use Application Manager to validate that the patches were correctly installed.
Community Votes
AB
78%
AD
22%
78% of anonymous learners picked answer AB.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Patch Manager approves patches per the baseline's auto-approval delay; setting it to 0 days makes security-classified patches available immediately. Patch Now triggers an on-demand install across nodes without waiting for a scheduled window, and directing the operation log output to an S3 bucket gives the centralized, auditable record of successful patching.
A media company needs to push security patches to its EC2 fleet on demand during an incident and prove they were applied. The solution is to set a patching baseline with Security classification, 0-day automatic approval, and make it the default for Amazon Linux 2, then use Patch Manager's Patch Now (scan and install) against that baseline and store the patch operation logs in an S3 bucket as centralized evidence.
Relying only on a patch policy with an hourly scan schedule (option D) instead of the immediate Patch Now action, or cloning the built-in baseline with a 1-day approval delay that still lags during an active incident.
Community Discussion (8 comments)
phmeeeee👍 1Selected: AB
A - selected for security classification only. B - for immediately apply the patch which is no need to schedule.
molerowan👍 1Selected: BD
B and D, for sure I guess D is an obvious answer, but the majority says it's A. Why I think other choices are wrong? A: While creating a baseline with 0-day approval accelerates patch availability, it doesn’t address immediate deployment or evidence. C: Reducing approval to 1 day still introduces delay and doesn’t enable on-demand action. E: Application Manager validates installations but lacks automated logging and isn’t designed for urgent deployments.
toshimizu👍 2Selected: AD
A,D correct
cumzle_com👍 4Selected: AB
A: Creating a new patching baseline with the specific settings ensures that security patches are automatically approved without delay (0 days). This immediate approval is crucial during a security incident when rapid patch deployment is necessary. Making this baseline the designated default for Amazon Linux 2 ensures that it is applied consistently across all instances. B: Using the Patch Now option with the scan and install operation ensures that patches are deployed immediately to all EC2 instances. By specifying an Amazon S3 bucket for log storage, the company can centrally store and review logs to provide evidence that the patches were applied successfully. This meets the requirement for centralized evidence of successful patch application.
sema2232👍 1
A,D correct
sema2232👍 2
why not D
5409b91👍 1Selected: AB
A & B are corrects!
Certified101👍 1Selected: AB
A & B are correct
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
A creates a dedicated Amazon Linux 2 baseline restricted to the Security classification with auto-approval at 0 days and sets it as the default, so security patches become eligible for install with no delay. B uses Patch Manager's Patch Now operation (scan and install) against that baseline across all managed nodes and sends the patch log output to an S3 bucket, satisfying both the immediate-deployment and centralized-evidence requirements.
Why the Other Options Are Wrong
C clones the built-in baseline but with a 1-day approval delay, which still lags during an active incident and does not meet the immediate need. D sets up a patch policy with an hourly custom scan schedule; scanning is not the same as immediate installation, and it lacks the on-demand Patch Now action. E (Application Manager) can inspect package versions but does not deploy patches or provide the required deployment evidence.
Community Comment Notes
The community favored A,B (70 votes). The leading comment explained that A's 0-day approval makes security patches available instantly and B's Patch Now applies them on demand with S3 log storage. A minority argued for A,D, but D only scans hourly and does not install immediately.