Amazon DOP-C02: Systems Manager, Patching and Operational Automation — Study Guide

Part of the AWS DevOps Engineer Professional DOP-C02 — Study Guide. Practice with verified answers in the Amazon exam hub, or take timed practice tests on ExamRoll.io.

Overview

Operational automation on AWS hinges on AWS Systems Manager, which unifies access control, configuration, patching, and remediation across EC2, on-premises servers, and edge. Surrounding services provide golden-image pipelines (EC2 Image Builder), license governance (AWS License Manager), continuous optimization (AWS Trusted Advisor and AWS Compute Optimizer), and cost controls (Savings Plans). The goal is standardized, auditable operations that are event-driven and enforceable across accounts and Regions.

Systems Manager Access, Parameters, Inventory, and Compliance

Systems Manager Session Manager provides interactive, auditable shell access to managed instances without opening inbound ports or managing SSH keys. You connect over the AWS control plane, optionally through VPC interface endpoints for private connectivity. Port forwarding enables secure access to local or remote services behind the instance:

Systems Manager Parameter Store centralizes configuration and secrets. Use SecureString parameters encrypted with a customer-managed KMS key for application secrets. Organize values into hierarchical paths (for example, /prod/payments/db/password) to enable environment and application scoping, policy scoping, and bulk operations. Parameter versioning maintains an immutable history; labels (such as current) let you point applications to a moving target without changing code. Dynamic references in CloudFormation, CodeBuild, and other services resolve parameters at deploy or runtime, preventing secret sprawl. The Standard tier provides basic throughput and 4 KB max value size; the Advanced tier supports parameter policies (expiration, rotation notifications), larger values (8 KB), and higher throughput. EventBridge rules can notify on parameter changes, and resource policies enable cross-account parameter sharing where needed.

Systems Manager Inventory and Compliance provide fleet-level visibility. Inventory (enabled via a State Manager association) collects metadata such as installed software packages, Windows roles, network adapters, and custom inventory items. Use Resource Data Sync to export to S3 for Athena/Glue analytics, and surface fleet-wide status in Systems Manager Explorer. Compliance aggregates patching and association states: you can see which instances are missing patches or have failed configuration baselines. This creates the operational data foundation required for automated remediation, audits, and license discovery.

Patch Manager and Operational Orchestration

Patch Manager standardizes OS and application patching using patch baselines, patch groups, and maintenance windows.

Patch baselines define what to approve and when. For each OS family, you can start with an AWS-provided default or build a custom baseline with:

Maintenance windows confine disruptive operations to safe timeframes. Define a schedule (rate/cron), duration, and cutoff to stop new tasks from starting near window end. Register targets by tags or resource groups, then register tasks with priority. Patch Manager integrates natively: register an AWS-RunPatchBaseline task for your patch groups and baselines. Concurrency and error-threshold settings on tasks prevent blast radius during failures.

Systems Manager Automation operationalizes repeatable, auditable remediation. Use built-in and custom runbooks to orchestrate pre- and post-patch activities (for example, drain from load balancer, stop app services, patch, run smoke tests, re-register), and to enforce controls via AWS Config remediation. Automation supports approvals (Change Manager), change calendars (to prevent execution during blackout periods), and cross-account/Region execution via assume-role. Tie everything together with Amazon EventBridge rules reacting to health events, config drift, or alarms to trigger targeted Automation executions for self-healing.

Golden Images with EC2 Image Builder

Immutable images reduce drift and shorten patch windows. EC2 Image Builder codifies AMI creation and distribution using pipelines, recipes, and distribution settings.

This pipeline approach pairs with Patch Manager: patch the AMI frequently to minimize instance patch deltas, then use maintenance windows for smaller delta patches on long-lived servers.

Governance, Licensing, and Cost Optimization

AWS License Manager governs bring-your-own-license (BYOL) and Marketplace entitlements. Define license configurations that model vendor rules (cores, sockets, vCPUs, host affinity, and virtualization constraints), choose hard or soft enforcement, and associate configurations with AMIs, launch templates, or instances. License Manager discovers software via Systems Manager Inventory to track consumption and prevent noncompliant launches. For Marketplace products that use License Manager entitlements, you can share grants across accounts and track entitlement usage centrally with a delegated administrator.

AWS Trusted Advisor continuously evaluates your environment against best practices. Categories include cost optimization, security, fault tolerance, service limits, performance, and operational excellence. With Business or Enterprise Support, you can access the full set of checks and the AWS Support API to refresh and retrieve results programmatically. Use EventBridge integration to route check status changes to remediation workflows (for example, trigger an Automation runbook to enable S3 default encryption or remove public access on a bucket), and enable Organizational View to aggregate across accounts with scoped IAM access and notifications to the right teams.

Cost optimization is continuous and data-driven:

Practical Problem Scenario

Company: Airbnb

Challenge: Airbnb operates multi-account, multi-Region EC2 workloads for data processing and web services. Security demands auditable, no-SSH access; compliance mandates timely security patching from both default and custom repositories; the platform team must standardize AMIs and reduce cost without performance risk. Software vendors impose core-based licensing for certain analytics nodes. Operations wants event-driven remediation and executive visibility across accounts.

Step-by-step approach:

  1. Enforce secure access with Systems Manager Session Manager
  1. Standardize configuration and visibility with Inventory and Compliance
  1. Define patch baselines and patch groups with custom repositories
  1. Schedule patching via Maintenance Windows with Automation pre/post steps
  1. Build golden images with EC2 Image Builder and publish to Parameter Store
  1. Govern vendor licenses with AWS License Manager
  1. Implement event-driven remediation and guardrails
  1. Optimize cost with Compute Optimizer and Savings Plans, governed by change control
  1. Monitor with Trusted Advisor organizationally

This integrated design delivers secure access, standardized patching, immutable AMIs, license compliance, automated remediation, and measurable cost optimization, all with auditable controls across Airbnb’s AWS footprint.


Networking and Content Delivery · All domains

Practice these questions → · Timed practice on ExamRoll.io →

Pass the whole exam — not just this question

You found this answer. Get every verified question and explanation in one place, and save hours of prep. Free to start.

Pass your exam →

Browse Amazon →

Related guides

All-in-one access

One subscription. Every exam.

Every plan unlocks unlimited answer search, practice tests, AI explanations, and the full resource library — in 20+ languages.

Monthly
24.87
Just €0.83/day
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

Best value
12 months
179.87
Just €0.49/daySave 40%
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

✓ Free plan included · ✓ Cancel anytime · ✓ All plans unlock the full product