A company needs to automate the execution of patch compliance checks and run administrative shell scripts across a fleet of Amazon EC2 instances. Security policies prohibit opening inbound SSH ports or using bastion hosts. Which AWS service should the company use to securely manage these operational tasks at scale?
- AAWS CloudFormation
- AWS Systems ManagerCevap
- CAWS Elastic Beanstalk
- DAmazon CloudWatch
Cevap
AWS Systems Manager is the correct service for managing operational tasks, running scripts, and automating patches securely across instances without SSH access.
The correct service is AWS Systems Manager because it provides features such as Run Command and Patch Manager. These allow administrators to execute scripts, apply patches, and check compliance across a fleet of EC2 instances via the Systems Manager Agent, eliminating the need to expose inbound SSH ports or manage bastion hosts.
Adım Adım Çözüm
Anahtar Kavram
AWS Systems Manager capabilities for configuration management and operational security
Tahmini Süre:1m 0s