A company uses AWS Systems Manager Patch Manager to automate patching of Amazon EC2 instances. The SysOps administrator needs to configure a maintenance window that will patch instances on the second Tuesday of every month at 2:00 AM. The administrator wants to ensure that patches are automatically applied but reboots are only performed if required. Which combination of configurations should the administrator use?
Trap 1: Create a maintenance window with a rate schedule of 30 days and use…
A rate schedule cannot specify a particular day of the week. The operation 'Scan' only checks for missing patches without installing them.
Trap 2: Create a maintenance window with a cron schedule of cron(0 2 14 * ?…
This cron schedule triggers on the 14th day of every month, not the second Tuesday.
Trap 3: Create a maintenance window with a cron schedule of cron(0 2 2 * 2…
The cron expression is invalid; the correct format uses ? for day-of-week and * for month. Also, AWS-InstallPatchBaseline is not a valid SSM document.
- A
Create a maintenance window with a cron schedule of cron(0 2 ? * TUE#2 *) and use an AWS-RunPatchBaseline document with operation 'Install' and reboot option 'RebootIfNeeded'.
The cron expression `0 2 ? * TUE#2 *` uses the `#` ordinal modifier to target the second Tuesday monthly, satisfying the schedule constraint. Pairing AWS-RunPatchBaseline with operation `Install` and reboot option `RebootIfNeeded` applies patches while rebooting only when the baseline requires it, matching the conditional-reboot requirement.
- B
Create a maintenance window with a rate schedule of 30 days and use an AWS-ApplyPatchBaseline document with operation 'Scan' and reboot option 'RebootIfNeeded'.
Why it fails: A rate schedule cannot specify a particular day of the week. The operation 'Scan' only checks for missing patches without installing them.
- C
Create a maintenance window with a cron schedule of cron(0 2 14 * ? *) and use an AWS-RunPatchBaseline document with operation 'Install' and reboot option 'RebootIfNeeded'.
Why it fails: This cron schedule triggers on the 14th day of every month, not the second Tuesday.
- D
Create a maintenance window with a cron schedule of cron(0 2 2 * 2 *) and use an AWS-InstallPatchBaseline document with operation 'Install' and reboot option 'NoReboot'.
Why it fails: The cron expression is invalid; the correct format uses ? for day-of-week and * for month. Also, AWS-InstallPatchBaseline is not a valid SSM document.