Question 1
A DevOps engineer needs to implement a solution to install antivirus software on all the Amazon EC2 instances in an AWS account. The EC2 instances run the most recent version of Amazon Linux.
The solution must detect all instances and must use an AWS Systems Manager document to install the software if the software is not present.
Which solution will meet these requirements?
Option A best matches the requirement in the simplest, most direct way:
Systems Manager State Manager is designed to apply and maintain a desired state on managed instances by running associations on a schedule or continuously across targets (for example, ''all managed nodes'').
By using a Systems Manager document in the association that installs the antivirus package (and can be written to be idempotent: ''install only if not present''), State Manager both detects drift (software missing) and remediates it automatically by reapplying the desired configuration.
This approach automatically covers all instances that are managed by Systems Manager (which is typically the standard requirement for fleet management on Amazon Linux).
Why the others are more overhead or not as direct:
B can work, but it requires building and operating a custom Config rule plus remediation wiring. That's more components and maintenance than State Manager for a straightforward ''ensure software is installed'' task.
C Amazon Inspector is a vulnerability management service; it's not the primary tool for ''ensure a specific software package is installed everywhere'' and ''remediate via SSM doc'' as a desired-state control.
D only detects new instances at launch time via CloudTrail RunInstances, and then you still need Inventory correlation logic. It's more complex and can miss already-running instances unless additional logic is added.