Courseiva

CLF-C02 Cloud Technology and Services Practice Question

A company runs a fleet of 100 EC2 instances and needs to remotely execute commands, apply patches, and collect inventory data across all instances without opening SSH ports. Which AWS service enables this?

⚠ Common exam trap

Test-takers frequently confuse Amazon EC2 Instance Connect (which still requires SSH port 22 to be open) with a solution that avoids opening ports entirely, or they mistakenly think AWS CloudShell can directly manage EC2 instances, when it is only a shell for the AWS CLI.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Systems Manager

AWS Systems Manager is the correct service because it provides a unified interface to remotely execute commands, apply patches, and collect inventory data across EC2 instances without requiring SSH access. It uses the Systems Manager Agent (SSM Agent) installed on the instances and communicates over HTTPS (port 443), eliminating the need to open inbound SSH ports (port 22). This aligns directly with the requirement to manage a fleet of 100 instances securely and at scale.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudShell

    Why it's wrong here

    AWS CloudShell is a browser-based shell with credentials for the signed-in user, not a mechanism for running commands on 100 EC2 instances without SSH. It is tempting because it offers command-line access, but fleet-wide patching and inventory require the Systems Manager agent.

  • ✓

    AWS Systems Manager

    Why this is correct

    AWS Systems Manager Run Command executes commands and patches across managed instances via the SSM agent's outbound connection, requiring no inbound SSH ports. This satisfies the stem's constraint of remote execution and inventory collection without opening SSH.

  • ✗

    Amazon EC2 Instance Connect

    Why it's wrong here

    EC2 Instance Connect pushes a temporary SSH key to an instance, so it still relies on SSH connectivity and does not run commands, patch, or collect inventory across a fleet. It is tempting for browser-based access to a single instance, but fleet-wide command execution without open ports requires AWS Systems Manager.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records resource configuration changes and evaluates compliance rules; it neither executes commands nor applies patches on instances. It is tempting because it provides fleet-wide visibility, but inventory collection and remote command execution without SSH belong to AWS Systems Manager, not Config.

About these practice questions

This CLF-C02 question is part of Courseiva's 993-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.