Patch Manager in AWS Systems Manager is being used to apply updates to a set of EC2 instances. A patch baseline and maintenance window are configured, and instances are selected by a tag. What additional step is required so Systems Manager can access and patch those EC2 instances?
Choose an answer
Tap an option to check your answer.
Correct answer: Attach an IAM instance profile (EC2 role) with the required Systems Manager permissions to the instances..
Why this is the answer
For Systems Manager to manage EC2 instances, including patching, each instance must have an IAM instance profile (EC2 role) attached. This role grants the necessary permissions for the SSM Agent running on the instance to communicate with the Systems Manager service. Without these permissions, Systems Manager cannot execute commands or apply patches. Opening inbound ports is generally not required for Systems Manager to function, as it uses outbound connections to the Systems Manager endpoint. Creating a Systems Manager activation is for registering on-premises servers or VMs, not EC2 instances. While specifying instances directly is an option, tag-based selection is a valid and common method for targeting instances, so it's not an "additional step required" to enable patching functionality.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed