CV0-004 Operations and Support Practice Question
A company wants to implement automated patching for their Windows and Linux servers in AWS. They need to schedule patching during a maintenance window and have a rollback plan. Which service should they use?
⚠ Common exam trap
The trap is confusing Patch Manager with other AWS services that have overlapping capabilities. For example, Amazon Inspector finds vulnerabilities but does not patch, and AWS Config can check compliance but not remediate. Candidates might also think OpsWorks is still the go-to for patching, but it's not.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Systems Manager Patch Manager
AWS Systems Manager Patch Manager automates the process of patching fleets of Windows and Linux servers. It allows you to define patch baselines, schedule patching during maintenance windows, and even roll back patches if needed, making it the ideal service for this requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS OpsWorks
Why it's wrong here
AWS OpsWorks Stacks automates configuration through Chef recipes but reached end of life on 26 May 2024, so it cannot deliver supported patching. It is tempting because its lifecycle events could once run recipes on a schedule, which suited Chef-managed fleets before the service was retired.
- ✗
AWS Config
Why it's wrong here
AWS Config evaluates resource configuration against rules and records compliance changes; it detects drift but performs no patching and offers no rollback. It is tempting because it tracks patch compliance state, which suits continuous configuration auditing rather than remediation across Windows and Linux fleets.
- ✓
AWS Systems Manager Patch Manager
Why this is correct
AWS Systems Manager Patch Manager applies OS patches to Windows and Linux instances on a schedule, using maintenance windows and patch baselines. It supports compliance reporting and controlled rollback through baseline approval rules, meeting the maintenance-window and rollback requirements.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector continuously scans EC2 instances and container images for vulnerabilities and software inventory; it reports findings but never installs patches or schedules maintenance windows. It is tempting because it identifies missing patches, which suits vulnerability assessment and compliance reporting rather than remediation.
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.