DOP-C02 Configuration Management and IaC Practice Question
A DevOps team manages hundreds of EC2 instances using AWS Systems Manager State Manager. They need to ensure that a specific configuration (e.g., a custom firewall rule) is applied to all instances and remains enforced. Which THREE steps should they take? (Choose THREE.)
⚠ Common exam trap
Many exam-takers confuse AWS Config rules (which only detect drift) with State Manager associations (which both detect and automatically remediate drift), leading them to select Option C instead of Option E for enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the instances have an IAM role that allows Systems Manager to perform actions.
AWS Systems Manager requires instances to have an IAM role that grants the necessary permissions (e.g., AmazonSSMManagedInstanceCore) for the SSM Agent to communicate with the Systems Manager service. Without this role, State Manager cannot apply or enforce any configuration, including custom firewall rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ensure the instances have an IAM role that allows Systems Manager to perform actions.
Why this is correct
The SSM Agent running on each EC2 instance requires an IAM instance profile that grants Systems Manager API permissions, such as the AmazonSSMManagedInstanceCore managed policy. Without this role, the agent cannot register with the Systems Manager service or receive association requests, so any subsequent automation—including State Manager—will fail. This IAM prerequisite is non-negotiable and must be verified before creating associations or running documents.
- ✓
Create a State Manager association using a custom document that defines the firewall rule.
Why this is correct
State Manager associations are the correct mechanism for enforcing a desired configuration because they bind a Systems Manager document to a target set of instances and execute its steps, including custom firewall rule definitions. Unlike Run Command, an association is persistent and automatically reapplies the document's content to bring instances back in line when drift occurs. A custom document allows you to define the precise firewall rules, such as iptables or Windows Firewall commands, tailored to your environment.
- ✗
Use AWS Config rules to detect non-compliance.
Why it's wrong here
AWS Config rules are detective, not corrective: they continuously evaluate resources against compliance policies and report whether a resource is non-compliant, but they do not modify the instance. To actually enforce a firewall rule, you would need to pair Config with remediation actions or Systems Manager automation, which is indirect and not the primary desired-state enforcement tool. Therefore, Config alone is insufficient for the stated requirement of ensuring the firewall rule stays applied.
- ✗
Use Run Command to execute the configuration once.
Why it's wrong here
Run Command executes a document or command once on target instances, making it ideal for immediate, one-off tasks like rebooting or ad-hoc patching. After the execution finishes, Systems Manager keeps no ongoing state guarantee, so if the firewall rule is later disabled or altered, nothing will reapply it. Even scheduling Run Command through CloudWatch Events or Maintenance Windows still results in independent fire-and-forget executions rather than a stateful association that tracks and enforces desired state.
- ✓
Set the association to apply the configuration on a schedule (e.g., every 30 minutes).
Why this is correct
Associations accept schedule expressions (cron or rate) that control how frequently the State Manager document re-runs against the targeted instances. By setting a schedule like every 30 minutes, the association detects and corrects configuration drift in the firewall rule on a recurring basis, ensuring continuous compliance. This scheduled reapplication is what differentiates State Manager from one-time Run Command and makes it a true desired-state configuration management service.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.