SOA-C02 Reliability and Business Continuity Practice Question
A company wants to ensure that its EC2 instances receive patches automatically to maintain security compliance. Which AWS service can be used to automate patch management?
⚠ Common exam trap
It's easy for candidates to confuse AWS Config's compliance evaluation with actual remediation actions, but Config only detects drift and can trigger automation via Systems Manager Automation documents—it does not directly patch instances.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Systems Manager
AWS Systems Manager Patch Manager automates the process of patching managed EC2 instances and on-premises servers. It uses patch baselines to define approved patches and can schedule patching across maintenance windows, ensuring security compliance without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon CloudWatch
Why it's wrong here
Amazon CloudWatch is a monitoring and observability service that collects metrics, logs, and events from AWS resources and applications. It does not have any capability to execute operating system commands, install packages, or apply security patches to EC2 instances. While CloudWatch alarms can trigger notifications or automated actions via Lambda or Systems Manager, the patching itself is performed by Systems Manager, not CloudWatch.
- ✓
AWS Systems Manager
Why this is correct
AWS Systems Manager Patch Manager automates the process of patching managed EC2 instances and on-premises servers. It uses the Systems Manager Agent (SSM Agent) to discover missing patches, download them from configured patch baselines, and install them according to maintenance window schedules. Patch Manager supports both Linux and Windows, including security updates, bug fixes, and non-security patches, and can generate compliance reports. This is the native AWS service designed specifically for patch management.
- ✗
AWS Config
Why it's wrong here
AWS Config is a compliance and configuration auditing service that records configuration changes to AWS resources and evaluates them against desired policies. It can detect whether an EC2 instance is out of compliance with patch rules using managed config rules like ec2-managedinstance-patch-compliance, but it does not actually install or apply patches. To remediate a non-compliant instance, AWS Config would need to invoke a Systems Manager Automation document, meaning the actual patching still falls to Systems Manager.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail is an API activity logging service that records all AWS API calls made by users, roles, or AWS services, providing an audit history of actions like RunInstances or SendCommand. It does not interact with the operating system of an EC2 instance and cannot determine or install pending security patches. CloudTrail serves as a forensic and operational audit tool, useful for seeing when a patching action was initiated, but it has no role in actually applying patches to instances.
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.