Soru

Zorluk: KolayAWS Systems Manager Configuration and Run Command Automation

A SysOps Administrator is troubleshooting a fleet of Amazon EC2 instances that fail to appear as managed nodes in the AWS Systems Manager console. The SSM Agent is installed and running on all instances, but no IAM role is currently attached to them. The instances are located in a public subnet with a route to an Internet Gateway and have public IPv4 addresses. Which action will allow the instances to register as managed nodes with Systems Manager?

  1. Attach an IAM instance profile containing the AmazonSSMManagedInstanceCore managed policy to the EC2 instances.Cevap
  2. B
    Add the iam:PassRole permission to the SysOps Administrator's IAM user policy.
  3. C
    Add a route targeting a Gateway VPC Endpoint for Systems Manager in the subnet's route table.
  4. D
    Assign a Patch Group tag to the EC2 instances that matches the Systems Manager patch baseline.

Cevap

Attach an IAM instance profile containing the AmazonSSMManagedInstanceCore managed policy to the EC2 instances.
For an EC2 instance to register as a managed node with AWS Systems Manager, it must meet three requirements: the SSM Agent must be installed and running, the instance must have network connectivity to Systems Manager endpoints, and an IAM instance profile containing the AmazonSSMManagedInstanceCore policy must be attached. Since the SSM Agent is running and the instances have internet access, attaching the correct IAM instance profile completes the prerequisites and allows registration.

Adım Adım Çözüm

1
Verify that the SSM Agent is running on the instances and that they have network connectivity to the Systems Manager service.
The SSM Agent is running and the instances are in a public subnet with a route to an Internet Gateway.
This rules out agent status and network path issues.
2
Identify the authorization requirements for an EC2 instance to register as a managed node.
The instance must have an IAM instance profile attached that permits communication with the Systems Manager APIs.
Without an IAM role, the instance cannot authenticate and register with the service.
3
Select the correct IAM role configuration to attach to the instances.
Attach an IAM instance profile containing the AWS-managed AmazonSSMManagedInstanceCore policy.
This policy provides the minimum required permissions for Systems Manager core functionality.

Anahtar Kavram

Systems Manager Managed Node Prerequisites
Tahmini Süre:1m 0s
Bu soruyu puanla