Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A company uses AWS Systems Manager Patch Manager to patch EC2 instances. During a security incident, the security team needs to quickly patch a critical vulnerability across all Windows instances in a specific AWS region. Which steps should the team take? (Choose TWO.)

⚠ Common exam trap

Test-takers frequently confuse tagging instances with a patch group (which is necessary for association) with the actual patching action, or they assume the default patch baseline will automatically include all critical patches, when in fact custom baselines are required for targeted incident response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign the patch baseline to the instances by specifying a patch group.

Assigning a custom patch baseline to instances via a patch group allows the security team to target specific Windows instances for patching. Patch Manager uses patch groups to associate instances with a specific patch baseline, ensuring only the desired instances receive the critical patch. This approach provides granular control over which instances are patched during an incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Assign the patch baseline to the instances by specifying a patch group.

    Why this is correct

    Patch groups in Systems Manager Patch Manager are defined by tagging managed nodes with the key `Patch Group` (case-sensitive) and then associating that group to a patch baseline using `Register-PatchBaselineForPatchGroup`. This association is what directs Patch Manager to evaluate and apply the baseline, including approval rules and custom patches, to every instance in that group. Without the explicit patch-group-to-baseline registration, simply having a tag on instances does not change which baseline is applied; the baseline must be knowingly assigned to the group.

  • ✗

    Tag all instances with 'PatchGroup=Critical' to include them in the patching.

    Why it's wrong here

    Tagging instances with `PatchGroup=Critical` only creates a patch group label; it does not by itself include them in any patching activity because AWS does not recognize a tag key of `PatchGroup` unless you have also registered that group to a patch baseline. Patch Manager uses the tag key exactly as `Patch Group` (with a space) when auto-associating groups, but even then the crucial missing step is calling `Register-PatchBaselineForPatchGroup` to assign a baseline. Merely tagging instances cannot cause them to receive a specific patch or be included in a patching schedule; the tag is the group membership mechanic, not the assignment action.

  • ✓

    Create a custom patch baseline that includes the required patch.

    Why this is correct

    Creating a custom patch baseline that explicitly approves the required patch is a valid prerequisite, but it does not by itself patch any instances; the baseline must be assigned to the instances via a patch group or as the default baseline. The custom baseline allows you to control the approval of that specific patch (e.g., by adding it to the ApproveAfterDays list or using a patch filter), yet without attaching the baseline to the instances through a patch group association, no scanning or patching occurs. So while this is part of the correct solution, the decisive action that makes the baseline effective is binding it to the target instances via a patch group assignment.

  • ✗

    Use the AWS-provided default patch baseline for Windows.

    Why it's wrong here

    The AWS-provided default patch baseline for Windows contains Microsoft's default patch selection rules, which typically approve updates based on classification and severity with an auto-approval delay, but a newly required critical patch may not be approved immediately if it falls outside the default auto-approval window or is not yet classified. Since the company must patch a specific critical patch that is 'required now', relying on the default baseline could leave the patch unapplied until the next auto-approval cycle that covers it. A custom baseline with an explicit approval rule for that patch (or an immediate approval) is needed to ensure it is installed deterministically, whereas the default baseline has no guarantee.

  • ✗

    Use SSM Run Command to execute a script that downloads and installs the patch.

    Why it's wrong here

    While SSM Run Command can execute a script to download and install a patch manually, it circumvents Patch Manager's lifecycle of patch scanning, compliance reporting, and baseline-based approval, leaving the instance out of the centralized patch management and audit trail. More importantly, the question asks for a Patch Manager-based approach, and Systems Manager Patch Manager itself uses Run Command under the hood to perform patching; manually scripting the install is brittle, lacks the patch baseline compliance integration, and does not register the patch in the Patch Manager console. Therefore, the intended and more reliable solution is to define a patch group and assign a custom baseline, not to launch an ad-hoc Run Command script.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.