The company runs servers on premises and in AWS. A SysOps administrator needs to automate tasks across all on-premises servers using AWS tooling but must avoid placing long-lived credentials on those servers. What is the recommended way to register and manage the on-premises servers with AWS for automation?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a managed-instance activation in AWS Systems Manager. Install the Systems Manager Agent (SSM Agent) on the on-premises servers, then register them using the activation code and ID..
Why this is the answer
The correct approach is to create a managed-instance activation in AWS Systems Manager. This generates an activation code and ID which are then used during the installation of the Systems Manager Agent (SSM Agent) on the on-premises servers. This method securely registers the on-premises servers with AWS Systems Manager without requiring long-lived AWS credentials directly on the servers, aligning with the security requirement. Creating an IAM role and instance profile is for EC2 instances, not on-premises servers. Creating an AWS managed IAM policy and downloading it doesn't provide a mechanism for authentication or registration. Creating an IAM user with an access key and storing it on the servers violates the requirement to avoid long-lived credentials on the servers.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed