Courseiva

Troubleshooting State Manager Associations Not Applying to New Instances

A company runs a production e-commerce platform on AWS. The architecture includes an Application Load Balancer (ALB) distributing traffic across EC2 instances in an Auto Scaling group. The application uses a custom configuration stored in an S3 bucket. The DevOps team uses AWS CodeDeploy to deploy application updates. Recently, a deployment failed because new instances launched by the Auto Scaling group did not have the latest configuration from S3. The team had manually updated the configuration in S3 but the deployment did not pull the new version. The team wants to ensure that all instances always have the latest configuration at launch. Current setup: The Auto Scaling group uses a launch template that specifies an IAM instance profile with permissions to read from S3. The user data script runs at launch to download configuration from S3. However, the user data script is static and does not account for configuration updates. The team wants a solution that automatically applies configuration changes to both existing and new instances without manual intervention.

⚠ Common exam trap

The trap is choosing solutions that only address new instances or require manual intervention. Candidates might think updating the launch template is sufficient, but it does not update existing instances or automatically apply changes when the S3 object is updated.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Systems Manager State Manager to associate a document that runs on all instances to fetch the latest configuration from S3 on a schedule and at instance startup.

AWS Systems Manager State Manager can associate a document with instances to run on a schedule and at instance startup, ensuring they fetch the latest configuration from S3. This automatically applies configuration changes to both existing and new instances without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Config with a custom rule to detect instances that do not have the latest configuration and trigger a Lambda function to update them.

    Why it's wrong here

    AWS Config is a governance tool that records and evaluates resource configurations against rules, but it does not natively enforce or remediate. A custom rule would only detect non-compliance and trigger a Lambda remediation asynchronously after the fact, leaving a window where instances run outdated configuration. Config also does not trigger automatically on instance startup, so new instances would need a separate evaluation trigger, making this approach reactive and not suitable for ensuring the latest config is always applied.

  • ✗

    Update the launch template with a new user data script that always fetches the latest configuration from S3. Then, update the Auto Scaling group to use the new launch template version.

    Why it's wrong here

    Updating a launch template and pointing the Auto Scaling group to the new version only affects newly launched instances. Existing instances in the group continue to run with the old user data script until they are terminated or replaced, so their configuration is not updated. Additionally, user data scripts execute only once during the first boot, so even if the template is updated, instances that are later rebooted won't re-run the script to fetch the latest configuration.

  • ✗

    Configure AWS CodeDeploy to deploy the configuration to all instances whenever the S3 object is updated, using an S3 event notification.

    Why it's wrong here

    CodeDeploy deployments are explicit actions that deploy a revision to a fleet; an S3 event notification can invoke a Lambda to call CodeDeploy, but it is not automatically connected to instance launches. Without a lifecycle hook or instance refresh trigger, a new instance added to an Auto Scaling group will not be included in a CodeDeploy deployment unless it is part of the deployment group and a deployment is initiated. This approach is also event-driven on the S3 object update only, not on instance startup, so new or restarted instances may miss the latest configuration.

  • ✓

    Use AWS Systems Manager State Manager to associate a document that runs on all instances to fetch the latest configuration from S3 on a schedule and at instance startup.

    Why this is correct

    State Manager is AWS Systems Manager's configuration management feature that lets you create associations between documents and EC2 instances, selected via tags or resource groups. Because the association targets are evaluated dynamically, new instances that match the tag get the association automatically, and existing instances are handled on the next scheduled run or at startup. You can schedule the association with a rate or cron expression, and also trigger it on instance startup, ensuring the S3 configuration is fetched on a regular basis and after each boot, making it proactive and fully automated.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.