Question 1 of 30
A company is using AWS Systems Manager to manage its fleet of EC2 instances across multiple regions. They want to ensure that all instances are compliant with a specific security policy that requires the installation of a particular software package and the configuration of a firewall rule. The company has set up a compliance rule in Systems Manager and scheduled a compliance scan to run every 24 hours. After the first scan, they find that 80% of their instances are compliant. However, they notice that 10% of the non-compliant instances are in a specific region. To address this, they decide to create a Systems Manager Automation document that will automatically install the required software and configure the firewall rule for the non-compliant instances. What is the best approach to ensure that the Automation document is executed only on the non-compliant instances?
Use a Systems Manager State Manager association to target only the non-compliant instances based on the compliance status.
Manually tag the non-compliant instances and use those tags to execute the Automation document.
Create a CloudWatch alarm that triggers the Automation document when the compliance status changes.
Schedule the Automation document to run every hour across all instances and filter the results afterward.

Preparing for Amazon SOA-C02 AWS Certified SysOps Administrator – Associate (SOA-C02)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free