SOA-C02 Deployment, Provisioning, and Automation Practice Question
A SysOps administrator uses AWS Systems Manager Run Command to install software on a fleet of EC2 instances. The command fails on some instances with the error 'Instance ID not found'. What is the MOST likely cause?
⚠ Common exam trap
Many exam-takers confuse the 'Instance ID not found' error with network connectivity or instance state issues, but the root cause is almost always the absence of the SSM Agent or the required IAM role, not the instance being stopped or lacking tags.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SSM Agent is not installed or configured on the instances, or the instances lack the required IAM role.
The error 'Instance ID not found' indicates that Systems Manager Run Command cannot communicate with the SSM Agent on the target instances. This typically occurs when the SSM Agent is not installed, is not running, or the instance does not have an IAM role that grants the necessary permissions (e.g., AmazonSSMManagedInstanceCore) for Systems Manager to manage it. Without a valid agent and IAM role, the instance is not registered with Systems Manager, so Run Command cannot find its Instance ID.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user data script has overridden the SSM Agent.
Why it's wrong here
User data is a one-time bootstrap script executed by cloud-init or EC2Config at instance launch, not a persistent service. The SSM Agent is a separate, long-running process (amazon-ssm-agent or AmazonSSMAgent service) that starts at boot and maintains registration with Systems Manager. A user data script cannot override or replace the SSM Agent; even if it terminates the agent process, the service manager restarts it. The 'Instance ID not found' error specifically indicates the instance has never registered with Systems Manager, which is unrelated to any user data actions.
- ✗
The instances are not tagged with the correct key-value pair.
Why it's wrong here
Run Command supports targeting instances by tags, but tags are not a prerequisite for registration or for direct invocation by instance ID. If you call Run Command with a specific instance ID, Systems Manager checks its managed instances inventory; an 'Instance ID not found' error means the instance is not in that inventory at all. Missing or incorrect tags might prevent tag-based targeting, but they would not cause an 'ID not found' response. The root cause lies in the agent, IAM role, or network connectivity that enables registration.
- ✓
The SSM Agent is not installed or configured on the instances, or the instances lack the required IAM role.
Why this is correct
The SSM Agent is required for an EC2 instance to communicate with AWS Systems Manager and receive Run Command documents. Additionally, the instance must have an attached IAM role that grants the AmazonSSMManagedInstanceCore managed policy, allowing it to register, send heartbeats, and pull commands from the SSM service. Without both the agent running and the correct IAM permissions, the instance never appears in the Managed Instances list, so Run Command returns 'Instance ID not found' when you target it. This is the definitive cause when resolving this specific error.
- ✗
The instances are in a stopped state.
Why it's wrong here
Run Command cannot send commands to a stopped instance because the SSM Agent is not running, but that scenario produces a different error, such as 'Target instance is stopped' or 'Instance is not online.' Systems Manager still retains the instance registration and metadata, so it can locate the instance by ID. The message 'Instance ID not found' indicates the instance is unknown to Systems Manager, which happens only when the agent has never registered or has been deregistered. A stopped instance, by contrast, is merely offline but still recognized in the fleet.
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.