SOA-C02 Deployment, Provisioning, and Automation Practice Question
A company uses AWS Systems Manager to manage a fleet of EC2 instances. The Security Team requires that all instances have a specific security patch installed. A SysOps administrator needs to verify compliance across all instances. What is the MOST efficient way to accomplish this?
⚠ Common exam trap
SOA-C02 often tests the confusion between enforcing a patch (State Manager) and verifying compliance (Patch Manager); candidates must remember that Patch Manager can both scan and report on compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Systems Manager Patch Manager to scan and generate a compliance report.
AWS Systems Manager Patch Manager can scan instances for missing patches and generate a compliance report showing which instances are compliant or non-compliant with the patch baseline. This directly addresses the requirement to verify compliance across the fleet efficiently. It uses the patch baseline to define approved patches and reports on compliance status.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Config rules to check for the patch.
Why it's wrong here
AWS Config rules are not designed to inspect the operating system's internal state, such as the presence of a specific security patch within an EC2 instance. Config primarily assesses the configuration of AWS resources themselves, like ensuring instances use approved AMIs or have specific tags, rather than their internal software. It is tempting because Config is a compliance and auditing service, but it lacks the deep OS-level visibility required here. Config would be the correct choice for verifying compliance against AWS resource-level configurations, for example, checking if all EC2 instances are launched in a specific VPC or have encryption enabled.
- ✗
Use AWS Systems Manager State Manager to enforce the patch.
Why it's wrong here
State Manager is designed to maintain desired instance state by repeatedly applying configurations, but its primary role is enforcement, not audit reporting. While you could use it to run a patch operation on a schedule, it does not generate a dedicated compliance report that lists which patches are missing or installed across a fleet. The question asks to scan and produce a compliance report, which is native Patch Manager functionality; State Manager's output would require additional custom logic to produce such a report, making it an indirect and incomplete solution.
- ✗
Use AWS Systems Manager Inventory to collect software inventory.
Why it's wrong here
Inventory collects system-level metadata such as installed applications, Windows updates, and file details, but it does not evaluate that data against a specific required patch or maintain patch compliance baselines. It provides raw software lists, not a compliance report comparing installed patches to an approved patch set, so you would still need custom logic to interpret the inventory data. Moreover, Inventory does not enforce or report on the security patch installation status in the context of Patch Manager's compliance states (e.g., Installed, Missing, Failed), making it inappropriate for this requirement.
- ✓
Use AWS Systems Manager Patch Manager to scan and generate a compliance report.
Why this is correct
Patch Manager integrates with the SSM Agent to apply operating system patches and automatically generates compliance reports by default when used with Patch Manager scan operations. These reports classify instances as compliant or non-compliant, list missing patches, and support filtering by severity and patch baseline, exactly matching the need to scan and generate a compliance report. As a native Systems Manager capability, it provides the most direct and correct mechanism for assessing patch compliance across EC2 instances.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.