CCSP Cloud Security Operations Practice Question
A cloud operations team runs a mission-critical application on Amazon EC2 instances behind an Application Load Balancer. The security policy requires that the instances be patched monthly, but the team wants to minimize downtime and avoid manual patching. They decide to use AWS Systems Manager Patch Manager. Which configuration should they implement to meet the patching requirement while maintaining availability?
⚠ Common exam trap
The trap here is assuming that AWS Config or EventBridge can directly apply patches, when they are monitoring and orchestration services, not patch deployment tools.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a patch baseline, a maintenance window that targets the instances, and a patch group that associates the instances with the baseline.
Patch Manager simplifies patching by using patch baselines, patch groups, and maintenance windows. The baseline defines which patches are approved, the patch group associates instances with the baseline, and the maintenance window schedules the patching. This integrated approach automates patching, provides compliance visibility, and allows controlled rollout to maintain availability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Config rules to automatically apply patches when a new CVE is published, and configure an SNS topic to notify the team.
Why it's wrong here
AWS Config evaluates resource compliance but does not install patches. It can detect missing patches but cannot remediate by applying them. SNS only sends notifications; it does not perform patching. This approach would not meet the requirement to patch automatically and would leave instances unpatched.
- ✗
Enable automatic OS updates on the EC2 instances by configuring the operating system's update service to run daily.
Why it's wrong here
While OS-level automatic updates can apply patches, they do not provide the centralized control, compliance reporting, and scheduling that Patch Manager offers. They also risk applying patches during peak hours, causing unexpected reboots and downtime. This method lacks the orchestration needed for a mission-critical application.
- ✓
Create a patch baseline, a maintenance window that targets the instances, and a patch group that associates the instances with the baseline.
Why this is correct
This approach uses Patch Manager's core components: a patch baseline defines approved patches, a patch group links instances to the baseline, and a maintenance window schedules the patching during a defined period. It automates patching, reduces manual effort, and can be configured to patch one instance at a time or in batches, preserving availability.
- ✗
Create an Amazon EventBridge rule that triggers an AWS Lambda function to run yum update on each instance via AWS Systems Manager Run Command on a schedule.
Why it's wrong here
This is a custom solution that could work but requires significant development and maintenance. It does not leverage Patch Manager's built-in compliance reporting, patch baselines, or maintenance windows. It also lacks the ability to define approved and rejected patches, increasing the risk of unapproved changes.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.