SAP-C02 Rolling update Practice Question
A company runs a critical application on EC2 instances in an Auto Scaling group. They want to ensure that during a patching cycle, the application remains available and no requests are dropped. Which TWO strategies should they implement? (Choose TWO.)
⚠ Common exam trap
SAP-C02 often tests whether candidates conflate vulnerability detection (Inspector) with automated remediation, or assume that scaling out alone guarantees availability during patching.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a rolling update using a batch size of 50% with a pause time.
Option C is correct because a rolling update with a batch size of 50% and a pause time replaces instances in controlled waves, so the remaining healthy instances continue serving traffic and capacity never drops to zero, keeping the application available during patching. Option D is correct because an Auto Scaling lifecycle hook puts instances into a wait state (Terminating:Wait or Launching:Wait) so a custom action—such as draining connections, deregistering from the load balancer, or finishing in-flight requests—can complete before the instance is terminated, preventing dropped requests. Option A is not correct because simply raising desired capacity adds instances but does not orchestrate safe patching or connection draining, so requests can still be dropped when instances are replaced. Option B is not correct because stopping all instances simultaneously causes an outage and drops all requests, directly violating the availability requirement. Option E is not correct because Amazon Inspector is a vulnerability assessment service that detects issues; it does not automatically patch EC2 instances.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the desired capacity of the Auto Scaling group before patching.
Why it's wrong here
Raising desired capacity adds instances but does not itself remove instances from service gracefully; without connection draining and health-check-aware rolling replacement, requests still drop. It is tempting because scaling out before maintenance is a genuine availability tactic, and would be correct if paired with load balancer deregistration delay.
- ✗
Stop all instances at the same time to apply patches consistently.
Why it's wrong here
Stopping every instance simultaneously removes all capacity, so requests are dropped during patching. It is tempting because it applies patches consistently and quickly, and would suit a non-production environment where downtime is acceptable and speed matters more than availability.
- ✓
Perform a rolling update using a batch size of 50% with a pause time.
Why this is correct
A rolling update replaces instances in batches, so the remaining 50% of the Auto Scaling group continues serving traffic while each batch is patched. The pause time lets new instances pass health checks before the next batch begins, preventing dropped requests.
- ✓
Use an Auto Scaling lifecycle hook to wait for a custom action before terminating instances.
Why this is correct
A lifecycle hook pauses the instance at the terminating state, allowing a custom action such as draining connections or deregistering from the load balancer before shutdown. This ensures in-flight requests complete, directly preventing dropped requests during patching.
- ✗
Use Amazon Inspector to automatically patch instances.
Why it's wrong here
Amazon Inspector identifies vulnerabilities and generates findings; it does not patch instances or orchestrate maintenance windows. It is tempting because it is the AWS vulnerability management service, and would be the right choice if the requirement were continuous detection and prioritisation of software vulnerabilities rather than automated patching.
Go deeper
Related to this question
About these practice questions
This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.