SCS-C02 · Question #316
A security team must present a daily briefing to the CISO that includes a report of which of the company's thousands of EC2 instances and on-premises servers are missing the latest security patches. A
The correct answer is B. Use Systems Manger Patch Manger to generate the report of out of compliance instances/. Use the Systems Manger Patch Manger to generate the report and also install the missing patches The AWS Documentation mentions the following AWS Systems Manager Patch Manager automates the process of patching managed instances with security-related updates. For Linux-based instan
Question
A security team must present a daily briefing to the CISO that includes a report of which of the company's thousands of EC2 instances and on-premises servers are missing the latest security patches. All instances/servers must be brought into compliance within 24 hours so they do not show up on the next day's report. How can the security team fulfill these requirements?
Options
- AUse Amazon QuickSight and Cloud Trail to generate the report of out of compliance
- BUse Systems Manger Patch Manger to generate the report of out of compliance instances/
- CUse Systems Manger Patch Manger to generate the report of out of compliance instances/
- DUse Trusted Advisor to generate the report of out of compliance instances/servers.
How the community answered
(63 responses)- A14% (9)
- B76% (48)
- C6% (4)
- D3% (2)
Explanation
Use the Systems Manger Patch Manger to generate the report and also install the missing patches The AWS Documentation mentions the following AWS Systems Manager Patch Manager automates the process of patching managed instances with security-related updates. For Linux-based instances, you can also install patches for non-security updates. You can patch fleets of Amazon EC2 instances or your on-premises servers and virtual machines (VMs) by operating system type. This includes supported versions of Windows, Ubuntu Server, Red Hat Enterprise Linux (RHEL), SUSE Linux Enterprise Server (SLES), and Amazon Linux. You can scan instances to see only a report of missing patches, or you can scan and automatically install all missing patches. Option A is invalid because Amazon QuickSight and Cloud Trail cannot be used to generate the list of servers that don't meet compliance needs. Option C is wrong because deploying instances via new AMI'S would impact the applications hosted on these servers Option D is invalid because Amazon Trusted Advisor cannot be used to generate the list of servers that don't meet compliance needs. https://docs.aws.amazon.com/systems-manager/latest/userguide/systems-manager- patch.html
Topics
Community Discussion
No community discussion yet for this question.