exam questions

Exam AWS Certified SysOps Administrator - Associate All Questions

View all questions & answers for the AWS Certified SysOps Administrator - Associate exam

Exam AWS Certified SysOps Administrator - Associate topic 1 question 333 discussion

A SysOps administrator is responsible for more than 50 Amazon EC2 instances that are deployed in a single production AWS account. The EC2 instances are running several different operating systems. The company's standards require patching to be completed at least once a month.

The SysOps administrator wants to use AWS Systems Manager to reduce the number of hours the company spends on operating system patching each month.

Which combination of steps should the SysOps administrator take to meet these requirements? (Choose three.)

  • A. Group similar EC2 instances together into resource groups by using AWS Resource Groups.
  • B. Create a schedule in Systems Manager Patch Manager. Specify the appropriate resource group as the target.
  • C. Specify Systems Manager Automation runbooks to patch the operating systems. Register the runbooks as tasks in the maintenance window. Specify the appropriate resource group as the target.
  • D. Create a Systems Manager Automation runbook to monitor and control the state of the patches required. Apply the runbook to Systems Manager Patch Manager.
  • E. Create a single Systems Manager maintenance window for each resource group.
  • F. Configure Systems Manager Fleet Manager to apply a Systems Manager Automation runbook to the appropriate resource group.
Show Suggested Answer Hide Answer
Suggested Answer: ACE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Gomer
Highly Voted 1 year, 10 months ago
Selected Answer: ACE
A: I see a "Resource Group" as the same as a "Patch Group", other than it was created by AWS Resource Groups Service. As I see it, both just apply tags to AWS instances. B: I don't see the term "schedule" EVER being used with Patch Manager. I'm of the opinion that a "Maintenance Window" isn't the same thing in this context. C: See the SSM Runbooks for patching "AWS-RunPatchBaseline" D: I couldn't find an SSM Runbook for monitor/control patch states. E: Maintenance Window is Patch Group setting F: I can't find a reference for using Fleet Manager with Patch Manager or run books.
upvoted 11 times
Gomer
1 year, 10 months ago
Reference regarding patch related runbooks: https://docs.aws.amazon.com/systems-manager/latest/userguide/patch-manager-ssm-documents.html
upvoted 4 times
...
...
numark
Most Recent 4 months, 3 weeks ago
Selected Answer: ABC
E not correct because it would increase the administrative burden rather than reducing it.B, correct answer Patch Manager helps automate the process of patching managed instances. By creating a patching schedule and targeting the resource groups created in step A, the administrator can ensure that patching is performed consistently and in line with company standards.
upvoted 1 times
...
DeaconStJohn
1 year, 5 months ago
Selected Answer: ABD
A - Patch group B - patch manager policy D - Monitoring This is the best outcome I can see. from clickopsing on the console. I am able to create a patch policy which schedules install and scan activities based on custom cron or daily/weekly. I can deploy these by resource group in the UI. This policy seems to be a better practice than older methods such as run command or ssm baseline/maintenance window. The last point in the document mentions monitoring. I hope that AWS has followed their own documentation on best practices when I answer this in my exam. https://docs.aws.amazon.com/systems-manager/latest/userguide/patch-manager-console.html#:~:text=Verify%20that%20the,and%20investigate%20failures
upvoted 2 times
...
[Removed]
1 year, 9 months ago
AAAAAAAAAAAAAACCCCCCCCCCCCCCCCCCEEEEEEEEEEEEE
upvoted 2 times
...
jlmadvig
1 year, 9 months ago
Selected Answer: ABC
A: By grouping similar EC2 instances into resource groups, you can easily manage and apply patching configurations and schedules to specific sets of instances. This helps to organize and target the patching process effectively. B: Using Systems Manager Patch Manager, you can create a patching schedule that defines when the patching operations should occur. By specifying the appropriate resource group as the target, you ensure that the patching schedule is applied to the specific group of instances. C: Systems Manager Automation runbooks provide predefined workflows that can automate common operational tasks, such as patching. You can create and register Automation runbooks to handle the patching process for the operating systems on your EC2 instances. By specifying the appropriate resource group as the target for the runbooks, you ensure that the patching is applied to the specific group of instances.
upvoted 4 times
jlmadvig
1 year, 9 months ago
Sorry, I was so tired last night. Gomer is right. ACE
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago