Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A company is using AWS Systems Manager to manage configuration drift on EC2 instances. They want to automatically apply a baseline configuration to instances that have drifted from the desired state. Which Systems Manager capability should they use?

⚠ Common exam trap

Candidates often confuse Run Command with State Manager because both can execute commands, but Run Command is for one-time execution while State Manager is for ongoing, automated enforcement of a desired configuration state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Systems Manager State Manager

AWS Systems Manager State Manager is the correct capability because it is specifically designed to define and maintain consistent configuration states for EC2 instances and other AWS resources. It uses associations to automatically apply a baseline configuration and remediate drift on a schedule or when triggered, ensuring instances remain in the desired state without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Systems Manager Patch Manager

    Why it's wrong here

    AWS Systems Manager Patch Manager is purpose-built for managing OS and software patch compliance, not for enforcing arbitrary desired-state configurations. It can install updates or handle patch baselines, but it cannot detect or correct drift in non-patch configuration items such as file contents, registry keys, or service states. Therefore, while it addresses one subset of configuration, it does not meet a general configuration-drift remediation requirement.

  • ✗

    AWS Systems Manager Parameter Store

    Why it's wrong here

    AWS Systems Manager Parameter Store is a hierarchical data store for configuration values, secrets, and strings, but it has no agent or execution engine to apply those values to an instance. Storing a parameter does not trigger any action on EC2 or on-premises machines, so it cannot automatically remediate drift. It is a passive source of truth, not an active enforcement mechanism.

  • ✗

    AWS Systems Manager Run Command

    Why it's wrong here

    AWS Systems Manager Run Command lets you execute an SSM document or script on demand, but it is designed for one-off, manual, or event-triggered operations, not for continuously maintaining a desired state. After the command finishes, there is no ongoing monitoring or automatic re-application if the configuration changes, and no built-in compliance reporting tied to a static baseline. To remediate drift, you would have to manually rerun the command, which defeats an automated remediation workflow.

  • ✓

    AWS Systems Manager State Manager

    Why this is correct

    AWS Systems Manager State Manager creates associations that define a desired configuration state using SSM documents, and it automatically applies that state on a schedule or when an instance is launched. When a configured resource drifts from the desired state, State Manager detects and remediates it during the next association execution, and it provides compliance status for every managed instance. It is the correct service for ongoing, agent-managed configuration enforcement and drift correction.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses AWS Systems Manager to manage a fleet of EC2 instances. The operations team needs to run a script on all instances that are missing a specific security patch. Which Systems Manager capability should be used to accomplish this?

easy
  • A.Automation
  • B.State Manager
  • ✓ C.Run Command
  • D.Patch Manager

Why C: Run Command lets you execute an SSM document (including an arbitrary shell/PowerShell script) once, on demand, against a targeted fleet of instances -- exactly what's needed to run a one-time remediation script across all instances missing a specific patch. It returns per-instance output/status immediately so you can confirm the script ran successfully. State Manager, by contrast, is built for enforcing a recurring/continuous desired state via scheduled associations and compliance tracking; since the requirement here is a single ad hoc script execution with no mention of an ongoing schedule or compliance reporting, State Manager would be unnecessary overhead.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.