A SysOps administrator uses AWS Systems Manager Session Manager to open sessions to EC2 instances. After launching a new EC2 instance, it does not appear in the list of managed instances available for Session Manager, even though the Systems Manager Agent is installed and running. What is the most likely cause?
Choose an answer
Tap an option to check your answer.
Correct answer: The EC2 instance does not have an attached IAM role that allows Session Manager to connect to the EC2 instance..
Why this is the answer
For an EC2 instance to be managed by AWS Systems Manager, including Session Manager, it must have an IAM instance profile attached that grants the necessary permissions. Specifically, the role needs permissions like ssm:UpdateInstanceInformation and ssm:StartSession. Without this IAM role, the Systems Manager Agent (SSM Agent) running on the instance cannot register itself with the Systems Manager service, making the instance invisible in the list of managed instances. Incorrect options: Session Manager does not use SSH key pairs for authentication; it uses IAM roles and policies. Session Manager does not require SSH (port 22) to be open in security groups. It communicates over HTTPS (port 443) to the Systems Manager service endpoints. Session Manager automatically discovers instances that meet the requirements; manual entry of instance IDs into a "Session Manager configuration" is not how it operates.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed