DOP-C02 Configuration Management and IaC Practice Question
Which THREE are valid AWS Systems Manager capabilities for configuration management? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run Command
Run Command enables you to manage configuration by remotely executing commands on instances. Patch Manager automates the process of patching managed instances. State Manager helps you define and maintain the desired state of your instances. OpsCenter (B) is an operational data hub for viewing and resolving operational issues, not primarily for configuration management. Parameter Store (C) provides secure storage for configuration data and secrets, but it is a supporting service rather than a configuration management capability itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run Command
Why this is correct
Run Command is a valid Systems Manager capability because it lets you execute operational commands and scripts on EC2 instances and on-premises machines via the SSM agent, without opening inbound ports like SSH or RDP. It supports ad-hoc execution across targets defined by tags, resource groups, or individual instance IDs, with features like rate control, error thresholds, and integration with EventBridge for automation.
- ✗
OpsCenter
Why it's wrong here
OpsCenter is not a valid capability for the requested set because it is an incident-management feature that aggregates OpsItems from CloudWatch, AWS Config, and other sources, providing a single place to diagnose and remediate operational issues. While it is part of Systems Manager, it does not directly manage or configure instances itself; instead it serves as a command center for human operators, which is why it fails the qualification as a management capability.
- ✗
Parameter Store
Why it's wrong here
Parameter Store is not a valid management capability because it is a secure, hierarchical store for configuration data, secrets, and strings, optionally encrypted with KMS. Although it is deeply integrated with other Systems Manager capabilities—for example, Run Command and State Manager reference parameters—it is fundamentally a configuration repository, not a service that performs actions on managed instances, so it does not meet the definition of a capability that manages systems.
- ✓
Patch Manager
Why this is correct
Patch Manager is a valid Systems Manager capability because it automates the process of patching managed instances by defining patch baselines, scanning for missing patches, and applying them on a schedule or during maintenance windows. It provides compliance reports and can operate against both EC2 and hybrid on-premises instances, making it one of the core capabilities for maintaining security and operational consistency across a fleet.
- ✓
State Manager
Why this is correct
State Manager is a valid Systems Manager capability because it gives you a declarative way to define and enforce a desired configuration state on your managed instances using associations that reference SSM documents. These associations run on a recurring schedule to ensure software, scripts, or agent configurations remain in compliance, and they can also be triggered manually, distinguishing State Manager from the one-time command execution of Run Command.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.