Courseiva
Incident and Event Response →mediumMultiple Choice

DOP-C02 Incident and Event Response Practice Question

A company uses AWS Systems Manager Patch Manager to patch EC2 instances. During a patching window, some instances fail to apply patches. The engineer checks the SSM Agent logs and sees 'ERROR: Failed to download patch files from the source.' What is the most likely cause?

⚠ Common exam trap

Watch out — candidates often assume the error is due to IAM permissions or patch baseline misconfiguration, overlooking that the specific 'Failed to download' message is a classic symptom of network egress blocking, not authorization or configuration issues.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The security group or NACL is blocking outbound HTTPS traffic (port 443).

The error 'Failed to download patch files from the source' indicates that the SSM Agent on the instance cannot reach the patch source repositories (e.g., Windows Update, Amazon Linux repos, or custom patch sources). Systems Manager Patch Manager requires outbound HTTPS (port 443) connectivity to download patch metadata and binaries. If a security group or NACL blocks this traffic, the download fails, producing this exact error in the agent logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IAM instance profile does not grant ssm:UpdateInstanceInformation.

    Why it's wrong here

    The ssm:UpdateInstanceInformation permission is required by the SSM Agent to register with Systems Manager and send heartbeat and inventory data. Without it, the instance will not appear as a managed node, and patch operations will fail before any download is attempted. This is a control-plane authorization issue, completely separate from the data-plane network path needed to fetch patch binaries from repositories.

  • ✗

    The SSM Agent is outdated.

    Why it's wrong here

    An outdated SSM Agent can cause communication failures with the Systems Manager service, such as unsupported protocol negotiation or signature validation errors, often accompanied by an automatic agent update attempt. However, a patch download failure specifically occurs when the agent cannot reach the configured patch repositories over the network, which is a connectivity problem, not a version mismatch. The error message for an outdated agent would reference the agent version or an update step, not a repository timeout.

  • ✗

    The patch baseline is configured incorrectly.

    Why it's wrong here

    A misconfigured patch baseline defines which patches are approved or rejected based on rules and severity, leading to patches being skipped or marked as not applicable. The download step only happens after the agent has evaluated the patch as approved and applicable, so a baseline error would not cause a download failure. Patch baseline configuration controls policy, not network connectivity to patch sources, and cannot block the HTTPS traffic required for downloading patch files.

  • ✓

    The security group or NACL is blocking outbound HTTPS traffic (port 443).

    Why this is correct

    The SSM Agent downloads patch binaries directly from the configured patch repositories, such as Windows Update or Linux package mirrors, using HTTPS on TCP port 443. If the instance's security group or subnet NACL blocks outbound HTTPS, the agent cannot reach these repositories, leading to a patch download failure. This is the most common network-level cause, especially when the instance can otherwise communicate with the Systems Manager API but fails specifically during patch retrieval.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.