A company runs Amazon EC2 Linux instances. The security team received a report listing common vulnerability identifiers (CVEs) that may affect the instances. A security engineer must verify patch compliance, identify at-risk instances, and automatically apply the required patches. Which approach meets these needs?
Choose an answer
Tap an option to check your answer.
Correct answer: Use AWS Systems Manager Patch Manager to identify missing patches and related vulnerability identifiers on the instances, and also use Patch Manager to automate the patching process..
Why this is the answer
AWS Systems Manager Patch Manager is the correct choice because it directly addresses all requirements. Patch Manager can scan EC2 instances for missing patches, identify associated CVEs, and then automate the application of those patches. This single service provides a comprehensive solution for patch compliance, vulnerability identification, and automated remediation. AWS Shield Advanced is a DDoS protection service and does not identify missing patches or CVEs. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, not patch compliance or CVEs. Amazon Inspector is a vulnerability management service that can identify CVEs and missing patches, but it does not automate the patching process itself; it provides findings that would then need to be acted upon by another service like Patch Manager.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed