Courseiva

DOP-C02 Configuration Management and IaC Practice Question

An organization uses AWS System Manager Patch Manager to patch EC2 instances. The patches are not being applied to some instances. The instances are running Amazon Linux 2 and have the SSM Agent installed. What is the MOST likely reason for the failure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The instances are missing the required IAM role for Systems Manager.

Instances must have an IAM role that grants Systems Manager permissions to manage patches. Without this role, the SSM Agent cannot communicate with the Systems Manager service, preventing patch application. Option A is incorrect because instances can use VPC endpoints (e.g., AWS PrivateLink) to reach Systems Manager without internet access. Option B is incorrect: although an out-of-date SSM Agent can cause issues, the agent auto-updates by default, and the most common cause for patch failures is missing IAM permissions, not an outdated agent. Option D is incorrect because Amazon Linux 2 is a fully supported operating system for Patch Manager.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The instances do not have internet access to reach the Systems Manager endpoint.

    Why it's wrong here

    The lack of internet access does not prevent Systems Manager if you use VPC endpoints or AWS PrivateLink. In fact, Systems Manager recommends using VPC endpoints for instances in private subnets. The failure to patch is more likely due to the missing IAM role, which prevents the agent from authenticating regardless of network path.

  • ✗

    The SSM Agent is out of date and needs to be updated.

    Why it's wrong here

    While Patch Manager does require a minimum SSM Agent version, outdated agents typically produce a different error or appear as 'misconfigured' in the console. The SSM Agent can be updated independently of OS patches, and a missing IAM role would prevent the agent from even registering with Systems Manager, making it the primary issue.

  • ✓

    The instances are missing the required IAM role for Systems Manager.

    Why this is correct

    To allow the SSM Agent to call Systems Manager APIs, an instance must have an IAM instance profile with the AmazonSSMManagedInstanceCore managed policy. Without this role, the agent cannot authenticate, and the instance will not appear as a managed node in Patch Manager, so no patching can occur.

  • ✗

    The instances are not running a supported operating system.

    Why it's wrong here

    The specific scenario does not indicate an unsupported OS; Amazon Linux 2, for example, is fully supported by Patch Manager. Even if an OS were unsupported, Patch Manager would report an 'Unsupported Platform' error, whereas the symptoms here point to an authentication/registration failure caused by the missing IAM role.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.