Cloud / AWS Systems Manager Interview questions
Last updated
1. What is AWS Systems Manager?
AWS Systems Manager (SSM) is an AWS service for operating the machines you run - EC2 instances, on-premises servers, edge devices and VMs - from one place, without logging in to each one.
It lets you run commands, patch operating systems, keep configuration consistent, store parameters and secrets, open shell sessions, collect inventory and run automated runbooks. Most of this works through the SSM Agent on each node, which talks to the Systems Manager service over HTTPS.
A short interview answer: it is the operations hub for your fleet, covering node management, change management, application management and operations management.
Take quiz
By SSHing into each node from the console
By deploying a Lambda function inside every instance
Through the SSM Agent running on each node
Through a site-to-site VPN created per node
Patching operating systems
Storing configuration parameters
Opening shell sessions to instances
Hosting a relational database engine
2. What are the main capabilities of AWS Systems Manager?
Systems Manager groups its tools by purpose. The ones you are most likely to be asked about are below.
| Capability | What it does |
| Run Command | Runs scripts or commands on many nodes at once |
| Session Manager | Browser or CLI shell without SSH or open ports |
| State Manager | Keeps nodes in a desired state on a schedule |
| Patch Manager | Scans and installs OS and application patches |
| Automation | Runs multi-step runbooks across AWS resources |
| Parameter Store | Stores configuration values and secrets |
| Inventory | Collects software and configuration metadata |
| Maintenance Windows | Defines safe time slots for disruptive tasks |
| Fleet Manager | Console view of nodes: files, registry, users, RDP |
All of them rely on the node being a managed node, meaning the SSM Agent is running and has permissions.
Take quiz
State Manager
Session Manager
Inventory
Parameter Store
Fleet Manager
Parameter Store
Distributor
OpsCenter
3. What is a managed node in Systems Manager?
A managed node is any machine that Systems Manager can manage: an EC2 instance, an on-premises server, an edge device or a VM in another cloud or data center.
To qualify, a node needs three things: the SSM Agent installed and running, an IAM identity that allows it to call Systems Manager, and outbound HTTPS connectivity to the Systems Manager endpoints.
EC2 instances show up with IDs like i-0abc..., while hybrid nodes registered through an activation get IDs prefixed with mi-. If a node does not appear under Fleet Manager, one of those three requirements is usually missing.
Take quiz
i-
hy-
mi-
ssm-
SSM Agent running
IAM permissions for Systems Manager
Outbound HTTPS to the SSM endpoints
An inbound rule on port 22
4. What is SSM Agent?
SSM Agent is the lightweight software installed on a node that receives requests from Systems Manager, executes them and reports back. Run Command, Session Manager, Patch Manager and State Manager all depend on it.
It is preinstalled on Amazon Linux 2 and 2023, recent Ubuntu AMIs and Windows Server AMIs from AWS. On other systems you install the package yourself.
The agent only makes outbound HTTPS calls (port 443) to the ssm, ssmmessages and ec2messages endpoints, which is why no inbound firewall rule is needed.
sudo systemctl status amazon-ssm-agent sudo tail -f /var/log/amazon/ssm/amazon-ssm-agent.log
Take quiz
Outbound HTTPS on port 443
Inbound SSH on port 22
Inbound HTTP on port 80
Inbound RDP on port 3389
/var/log/ssm/agent.out
/var/log/amazon/ssm/amazon-ssm-agent.log
/etc/amazon/ssm/log.txt
/opt/aws/ssm/agent.log
5. What IAM permissions does an EC2 instance need for Systems Manager?
The instance needs an instance profile whose role allows the SSM Agent to talk to Systems Manager. The simplest option is attaching the AWS managed policy AmazonSSMManagedInstanceCore.
That policy covers registration, receiving commands, Session Manager connections and basic messaging. Add more only when needed - for example S3 read access for patch or document downloads, or KMS access for encrypted parameters and session logs.
Note that the role is for the instance. The person or pipeline calling Systems Manager (for example running SendCommand) needs separate IAM permissions on their own identity.
Take quiz
AmazonEC2FullAccess
AdministratorAccess
AmazonSSMManagedInstanceCore
AWSSystemsManagerOwnerAccess-Instance
Only the target instance profile
Only the VPC endpoint
Nobody, SendCommand is unauthenticated
The user or role issuing the command
6. What is SSM Parameter Store?
Parameter Store is a Systems Manager capability for storing configuration data and secrets as named parameters - database URLs, feature flags, AMI IDs, license keys, passwords.
Values can be plain text or encrypted with KMS. You control access with IAM, and every change is versioned. Applications read parameters through the API or CLI instead of hard-coding values or baking them into images.
aws ssm put-parameter --name /myapp/prod/db/url --value "db.example.internal" --type String aws ssm get-parameter --name /myapp/prod/db/url
The standard tier is free, which makes it a popular first choice for non-rotating configuration.
Take quiz
A new version of the parameter
A new IAM role
A new KMS key
A new VPC endpoint
Streaming log data
Centralised app configuration kept out of code
Running containers
Hosting static websites
7. What are the parameter types in Parameter Store?
Parameter Store supports three types.
- String - a plain text value such as a URL or a flag.
- StringList - comma-separated values stored as one parameter, for example
us-east-1,us-west-2. - SecureString - a value encrypted with a KMS key, used for passwords, tokens and keys.
For SecureString you can use the default aws/ssm key or a customer managed key. Reading the plain value requires the --with-decryption flag plus KMS decrypt permission.
Take quiz
String
StringList
SecureString
Secret
A JSON document up to 1 MB
A binary file
A pointer to an S3 object
Comma-separated values in one parameter
8. What is Session Manager in AWS Systems Manager?
Session Manager gives you an interactive shell (bash, PowerShell) on a managed node from the AWS console or CLI, with no SSH keys, no bastion host and no inbound ports.
Access is controlled by IAM, every session is tied to a user identity, and you can record sessions to S3 or CloudWatch Logs for audit. It also supports port forwarding to reach private databases or web apps.
aws ssm start-session --target i-0123456789abcdef0
The CLI needs the Session Manager plugin installed locally.
Take quiz
Inbound SSH ports and bastion hosts
IAM policies
The SSM Agent
Outbound internet access of any kind
An OpenSSH server
The Session Manager plugin
A VPN client
The Docker engine
9. What is Run Command in AWS Systems Manager?
Run Command executes commands or scripts on one or many managed nodes remotely, safely and with an audit trail. You pick a document, choose targets, and Systems Manager handles delivery and status.
Typical documents are AWS-RunShellScript for Linux and AWS-RunPowerShellScript for Windows. Targets can be instance IDs, tags or resource groups, and you can limit blast radius with max concurrency and max errors.
aws ssm send-command --document-name AWS-RunShellScript \ --targets Key=tag:Env,Values=staging \ --parameters commands="uptime"
Output goes to the console, or to S3 or CloudWatch Logs if you need the complete text.
Take quiz
AWS-RunPowerShellScript
AWS-ApplyPatchBaseline
AWS-RunShellScript
AWS-StartSSHSession
Max errors
Cutoff time
Output S3 prefix
Max concurrency
10. What is an SSM document?
An SSM document is a JSON or YAML file that defines the actions Systems Manager performs on your nodes or resources. It is the "what to do" part of Run Command, State Manager, Automation and Session Manager.
Common document types are Command (Run Command and State Manager), Automation (runbooks), Session, Package (Distributor) and ChangeCalendar. AWS provides many documents prefixed AWS-, and you can author your own and share them with other accounts.
schemaVersion: '2.2' description: Print hostname mainSteps: - action: aws:runShellScript name: hostname inputs: runCommand: - hostname
Take quiz
JSON or YAML
XML only
Plain binary
Terraform HCL
Command
Automation
Policy
Package
11. What is State Manager in AWS Systems Manager?
State Manager keeps your nodes and AWS resources in a defined state through associations. An association links a document, a set of targets and a schedule.
For example, an association can run AWS-UpdateSSMAgent weekly on every node tagged Env=prod, or ensure an antivirus package stays installed. If the node drifts, the next scheduled run puts it back.
Results show up as association compliance, so you can see which nodes are compliant and which failed.
Take quiz
A baseline
A maintenance window
An association
A session
The node is terminated
Nothing, State Manager only reports once
The node is moved to another VPC
The next association run corrects it
12. What is Patch Manager in AWS Systems Manager?
Patch Manager automates scanning for and installing operating system and application patches on managed nodes, using rules you define in a patch baseline.
It supports Windows, Linux distributions and macOS. You can scan only to report compliance, or install patches during a maintenance window, and view per-node results in the Patch Manager dashboard.
The work is executed by the AWS-RunPatchBaseline document, usually triggered by a maintenance window, State Manager association or patch policy.
Take quiz
AWS-RunPatchBaseline
AWS-RunShellScript
AWS-UpdateLinuxAmi
AWS-ConfigureCloudTrail
A security group
A patch baseline
A launch template
A VPC endpoint
13. What is a patch baseline in Systems Manager?
A patch baseline is the rule set that decides which patches are approved for installation. Rules filter by classification (Security, Bugfix), severity and product, and can add an auto-approval delay in days.
You can also hard-list approved or rejected patches. AWS supplies predefined baselines per operating system, such as AWS-DefaultPatchBaseline, which cannot be edited. Create a custom baseline when you need stricter or slower approval rules.
Each node uses one baseline per operating system - the default unless its patch group is registered to a custom one.
Take quiz
Delays instance boot
Delays the SSM Agent start
Waits a set number of days after release before approving a patch
Removes patches after a set time
Yes, from the console only
Yes, but only for Windows
Yes, with root access on a node
No, create a custom baseline instead
14. What is Systems Manager Automation?
Automation runs multi-step workflows called runbooks to perform common maintenance and deployment tasks on EC2 instances and other AWS resources - without scripting your own orchestration.
Each runbook is an Automation document made of steps like aws:executeAwsApi, aws:runCommand, aws:createImage, aws:approve and aws:branch. AWS provides runbooks for tasks such as restarting instances, creating AMIs, or remediating AWS Config findings.
Automation can be started from the console, CLI, EventBridge, a maintenance window or a State Manager association, and it runs with an AutomationAssumeRole.
Take quiz
Runbooks
Playbooks only
Baselines
Associations
InstanceProfileRole
AutomationAssumeRole
SessionManagerRole
PatchGroupRole
15. What is Maintenance Windows in AWS Systems Manager?
Maintenance Windows let you schedule disruptive actions, such as patching or restarts, during times that are safe for your workloads.
A window has a schedule (cron or rate), a duration, a cutoff, registered targets and registered tasks. Task types include Run Command, Automation, Lambda and Step Functions.
Tasks run in priority order, and no new tasks start once the cutoff time is reached, so you avoid work spilling past the allowed period.
Take quiz
Only Run Command
Only EC2 start and stop
Run Command, Automation, Lambda and Step Functions
Only CloudFormation stacks
Deletes the window
Terminates running tasks immediately
Changes the target tags
Stops new tasks starting before the window ends
16. What is Systems Manager Inventory?
Inventory collects metadata from managed nodes and shows what is installed and how each node is configured. It gathers installed applications, AWS components, network configuration, Windows updates, services, and instance details, plus any custom inventory you define.
Collection is configured through a State Manager association using AWS-GatherSoftwareInventory. The data can be queried in the console or exported through a resource data sync to S3 for analysis with Athena.
Take quiz
AWS-GatherSoftwareInventory
AWS-RunPatchBaseline
AWS-UpdateSSMAgent
AWS-RunInspecSecurityScan
A DynamoDB stream
An S3 bucket
An SQS queue
A Route 53 zone
17. What is Fleet Manager in AWS Systems Manager?
Fleet Manager is the console experience for managing your managed nodes remotely. From one screen you can see node health, browse file systems, view logs and performance counters, manage users and groups, edit the Windows registry and start remote desktop sessions.
It is handy for ad-hoc troubleshooting where you want a quick look at a node without opening a separate SSH or RDP tool. It uses the same SSM Agent and IAM permissions as the rest of Systems Manager.
Take quiz
Compiling .NET code
Creating VPC peering
Registry editor and remote desktop in the console
Changing S3 bucket policies
A dedicated bastion host
A NAT instance only
Inbound SSH keys
The SSM Agent and IAM permissions
18. What are Hybrid Activations in Systems Manager?
A hybrid activation lets you register non-EC2 machines, such as on-premises servers or VMs in another cloud, as managed nodes.
You create an activation with an IAM service role and get an activation code and ID. On each server you install SSM Agent and register it with those values. The activation expires after 24 hours by default and can be set up to 30 days, and you can cap how many machines register with it.
sudo amazon-ssm-agent -register -code "<code>" -id "<id>" -region "us-east-1"
Registered machines appear with mi- IDs.
Take quiz
An activation code and activation ID
An EC2 key pair
A VPC peering connection
An AMI copy
1 hour
24 hours
7 days
Never expires
19. What is Quick Setup in AWS Systems Manager?
Quick Setup is a guided way to configure common Systems Manager capabilities across accounts and Regions quickly, using best-practice defaults.
You pick a configuration type, such as host management, patch policy, or Explorer, then choose targets by tag or organizational unit. Quick Setup deploys the underlying associations and IAM roles using CloudFormation StackSets behind the scenes.
It is ideal when you want a working baseline for a new account or an entire AWS Organization without hand-building every association.
Take quiz
A new AWS Region
A managed database
Guided, best-practice setup across accounts and Regions
A container registry
Only by instance size
Only by AMI name
Only by subnet CIDR
By tags or organizational units
20. What is OpsCenter in AWS Systems Manager?
OpsCenter is a central place to view, investigate and resolve operational issues, which it tracks as OpsItems.
An OpsItem collects context such as the affected resource, related CloudWatch alarms, runbooks and similar past items. OpsItems can be created manually or automatically through EventBridge rules or alarms, and you can run Automation runbooks right from the item.
That means the on-call engineer sees the problem and the fix in one screen instead of jumping between consoles.
Take quiz
OpsItems
Associations
Baselines
Activations
Docker builds
Automation runbooks
Terraform plans
Glue crawlers
21. What is the difference between standard and advanced parameters?
Both tiers store the same types of parameters, but advanced parameters raise limits and add features.
| Feature | Standard | Advanced |
| Parameters per account and Region | 10,000 | 100,000 |
| Maximum value size | 4 KB | 8 KB |
| Parameter policies | No | Yes |
| Storage charge | Free | Charged per parameter |
Parameter policies add expiration and notification rules, which only advanced parameters support. You can upgrade a standard parameter to advanced, but you cannot downgrade it back.
Take quiz
Standard
Both equally
Advanced
Neither
Yes, at any time
Yes, but only for String type
Yes, if unused for 30 days
No, the upgrade is one way
22. How does Session Manager work without opening inbound ports?
Session Manager reverses the connection direction. The SSM Agent on the node opens an outbound HTTPS connection to the Systems Manager service, and the shell traffic travels over that connection.
When you start a session, the service authenticates you with IAM, then relays the session data between your client and the agent through the ssmmessages endpoint. Nothing in your security group needs to allow port 22 or 3389.
sequenceDiagram participant U as User participant S as Systems Manager participant A as SSM Agent U->>S: StartSession (IAM authenticated) A->>S: Outbound HTTPS channel already open S-->>A: Session request U->>S: Shell input S->>A: Relay input A-->>U: Shell output via service
This also means private instances without public IPs are reachable if they can reach the endpoints or VPC endpoints.
Take quiz
ssmmessages
s3-accelerate
sts-fips
autoscaling
Inbound from the internet to the node
Outbound from the node to the service
Inbound from your laptop directly
None, it uses UDP broadcast
23. Why is Session Manager better than SSH with a bastion host?
The main advantages are security, auditability and less maintenance.
- No inbound ports - no port 22 exposed, so nothing to scan or brute force.
- No key management - no SSH keys to rotate or leak; access follows IAM.
- Full audit trail - CloudTrail records who started a session, and session logs can go to S3 or CloudWatch Logs.
- No bastion to patch - one less instance to run, harden and pay for.
You can restrict access with IAM conditions on tags, for example allowing engineers to connect only to Env=dev. If you still need SSH tooling, SSH can be tunneled through Session Manager.
Take quiz
Shared SSH key pairs
Local Linux passwords only
IAM identities
Security group membership
Direct public IP access
Telnet
A Route 53 record
SSH tunneled through Session Manager
24. How do you log Session Manager sessions for audit?
There are two layers. CloudTrail always records the API calls such as StartSession and TerminateSession, showing who connected and when.
For the actual commands and output, enable session logging in the Session Manager preferences and choose a destination: an S3 bucket, a CloudWatch Logs log group, or both. You can encrypt the logs with KMS, and enable session data encryption for the stream itself.
The node's instance profile needs permission to write to the chosen bucket or log group, otherwise logging silently fails and sessions may be blocked if you require it.
Take quiz
AWS CloudTrail
VPC Flow Logs
AWS Config timeline
Trusted Advisor
Only to the instance's local disk
S3 or CloudWatch Logs
Only to SNS
Only to Route 53 query logs
25. How does Run Command execute a command on managed nodes?
Run Command is pull-based. You call SendCommand, Systems Manager records the request and queues it for the targets. Each SSM Agent polls the service, picks up its command, downloads and runs the document, and reports status back.
sequenceDiagram participant U as User participant S as Systems Manager participant A as SSM Agent U->>S: SendCommand (document, targets) A->>S: Poll for commands S-->>A: Command payload A->>A: Run document plugins A->>S: Status and output S-->>U: Invocation results
Each node gets its own command invocation with a status such as Pending, In Progress, Success, Failed or Timed Out. Large output is truncated in the console, so send it to S3 or CloudWatch Logs when you need all of it.
Take quiz
The service SSHes into the node
The node exposes a public API
It polls the service and picks up its command
A push over inbound port 22
A new AMI
A new subnet
A new IAM user
A command invocation with its own status
26. How do you target nodes and control rollout in Run Command?
Targets can be given as explicit instance IDs, as tags (for example Key=tag:Env,Values=prod), or as an AWS Resource Group. Tag targeting is preferred because new instances are picked up automatically.
For rollout safety, set max concurrency (how many nodes at once, number or percentage) and max errors (how many failures before Systems Manager stops sending to more nodes).
aws ssm send-command --document-name AWS-RunShellScript \ --targets Key=tag:Env,Values=prod \ --max-concurrency 10% --max-errors 1 \ --parameters commands="systemctl restart app"
With 10% concurrency and 1 error allowed, a bad script stops after hitting very few nodes.
Take quiz
How many failures are allowed before sending stops
Maximum output size
Maximum script length
Maximum number of tags
Tags make commands run faster
New tagged nodes are included automatically
Tags avoid needing IAM
Tags skip the SSM Agent
27. What is the difference between Run Command and State Manager?
Run Command is a one-time, on-demand action. State Manager is ongoing enforcement on a schedule.
| Aspect | Run Command | State Manager |
| Trigger | Manual or API call | Schedule and on association creation |
| Purpose | Ad-hoc tasks, one-off fixes | Keeping a desired state |
| Reporting | Per-command invocation status | Association compliance |
| Applies to new nodes | No, must be re-run | Yes, if they match the tags |
Use Run Command to restart a service right now. Use State Manager to make sure the CloudWatch agent is always installed and running.
Take quiz
Run Command
Fleet Manager
State Manager
Session Manager
State Manager association
Patch baseline
Inventory
Run Command
28. What is the difference between Parameter Store and Secrets Manager?
Both store sensitive values, but Secrets Manager is built for secrets that must be rotated, while Parameter Store is a broader, cheaper configuration store.
| Aspect | Parameter Store | Secrets Manager |
| Automatic rotation | No built-in rotation | Built-in, e.g. RDS credentials via Lambda |
| Cost | Standard tier free | Charged per secret and per API call |
| Max value size | 4 KB / 8 KB | 64 KB |
| Cross-account sharing | Limited, advanced tier shares | Resource policies |
| Best for | Config values, flags, simple secrets | Database credentials, API keys needing rotation |
Many teams use both: Parameter Store for general config, Secrets Manager for credentials. Parameter Store can even reference a secret through the /aws/reference/secretsmanager/ path.
Take quiz
Secrets Manager
Parameter Store standard tier
Systems Manager Inventory
AWS Config
Secrets Manager
Parameter Store standard tier
A KMS key per value
DynamoDB global tables
29. How do you store and read a SecureString parameter securely?
Create the parameter with --type SecureString, optionally naming your own KMS key with --key-id. The value is encrypted at rest and never shown in plain text unless the caller asks for decryption.
aws ssm put-parameter --name /myapp/prod/db/password \ --value 'S3cr3t!' --type SecureString --key-id alias/myapp-key aws ssm get-parameter --name /myapp/prod/db/password --with-decryption
The reader needs two permissions: ssm:GetParameter on the parameter ARN and kms:Decrypt on the key. With a customer managed key, the key policy must also allow that principal. Keep the value out of shell history by reading it from a file or stdin.
Take quiz
--decrypt-all
--show-secret
--with-decryption
--raw
s3:GetObject
ec2:DescribeInstances
iam:PassRole
kms:Decrypt on the key
30. How do you organize parameters with a hierarchy in Parameter Store?
Use slash-separated names like /app/env/component/setting, for example /shop/prod/db/host. Hierarchies let you fetch and secure parameters as groups.
The GetParametersByPath API returns all parameters under a path, with --recursive to include deeper levels. IAM policies can also target a path with a wildcard, such as arn:aws:ssm:*:*:parameter/shop/prod/*, so the prod app role cannot read dev values.
aws ssm get-parameters-by-path --path /shop/prod --recursive --with-decryption
A hierarchy can be up to 15 levels deep.
Take quiz
GetParametersByPath
ListParameters only
DescribeSessions
GetInventorySchema
To speed up KMS
To scope IAM access per environment
To enable rotation
To make parameters public
31. How does parameter versioning and labeling work in Parameter Store?
Every time you overwrite a parameter, Parameter Store creates a new version and keeps the history (up to 100 versions). You can read an older one by appending the version to the name, such as /app/color:2.
Labels are friendly pointers attached to a version, like prod or stable. Reading /app/color:prod returns whichever version carries that label, so you can promote or roll back by moving the label instead of changing application code.
aws ssm label-parameter-version --name /app/color --parameter-version 3 --labels stable
Take quiz
/app/color#2
/app/color?v=2
/app/color:2
/app/color/2
They encrypt the value
They raise throughput
They create backups in S3
Rollback or promotion without changing app code
32. How do parameter policies work in Parameter Store?
Parameter policies are available only on advanced parameters. They attach time-based rules to a parameter.
- Expiration - deletes the parameter at a set date and time.
- ExpirationNotification - sends an EventBridge event a number of days before it expires.
- NoChangeNotification - alerts you if the parameter has not been updated within a period.
This is useful for temporary credentials or tokens that must be rotated. Notifications arrive through Amazon EventBridge, which you can route to SNS, Lambda or OpsCenter.
Take quiz
Expiration
NoChangeNotification
ExpirationNotification
Rotation
By SMTP from the instance
Through Amazon EventBridge
By S3 event notification
By Run Command output
33. How does Patch Manager decide which patches to install?
Patch Manager looks at the node's operating system, finds its patch baseline (through patch group or the default) and evaluates available patches against that baseline.
A patch is installed if it matches an approval rule - by product, classification such as Security or CriticalUpdates, and severity - and the auto-approval delay has passed. Patches in the approved list are always included, and patches in the rejected list are excluded or only allowed as dependencies.
On Linux, the source is the node's configured package repositories. On Windows, it is Windows Update or WSUS.
Take quiz
It is always installed first
It is installed on reboot only
It is not installed, or only allowed as a dependency
It is installed on Windows only
Directly from the SSM service
An S3 bucket created by default
The AWS Marketplace
The node's configured package repositories
34. What is the difference between Scan and Install in AWS-RunPatchBaseline?
The Operation parameter of AWS-RunPatchBaseline decides what the run does.
| Operation | Scan | Install |
| Installs patches | No | Yes |
| Reports compliance | Yes | Yes |
| Reboots node | Never | Depends on RebootOption |
| Typical use | Daily compliance checks | Maintenance window patching |
A common pattern is a frequent Scan association for visibility, plus a scheduled Install task in a maintenance window. The RebootOption value (RebootIfNeeded or NoReboot) controls restarts after install.
Take quiz
Scan
Install
Rollback
Mirror
Operation set to Scan-Only-Reboot
RebootOption set to NoReboot
Baseline set to Disabled
Cutoff set to 0
35. How do patch groups work in Patch Manager?
A patch group associates a set of nodes with a specific patch baseline. You do it by tagging nodes with the key Patch Group (or PatchGroup) and a value like web-prod, then registering that value with a baseline.
aws ssm register-patch-baseline-for-patch-group \ --baseline-id pb-0123456789abcdef0 --patch-group web-prod
Nodes without the tag use the default baseline for their operating system. One node can belong to only one patch group, and a patch group can be registered to only one baseline per operating system. Patch policies in Quick Setup are the newer, organization-wide way to do the same job.
Take quiz
Baseline
SSM-Group
Patch Group
Patch-Target
No baseline, so it is never scanned
The newest custom baseline
A random baseline
The default baseline for its OS
36. Explain a patching workflow using Patch Manager and maintenance windows?
A typical production flow ties tags, baselines and a window together.
- Tag nodes with a patch group, such as
web-prod. - Create a custom baseline (for example Security patches, 7-day delay) and register it to the group.
- Create a maintenance window for Sunday night and target nodes by the patch group tag.
- Register a Run Command task with
AWS-RunPatchBaseline, Operation Install. - Review compliance in the Patch Manager dashboard afterwards.
flowchart LR A["Tag nodes: Patch Group"] --> B["Custom patch baseline"] B --> C["Maintenance window targets tag"] C --> D["AWS-RunPatchBaseline Install"] D --> E["Compliance report"]
Use rate controls on the task so only a portion of the fleet reboots at once.
Take quiz
AWS-RunPatchBaseline with Operation Install
AWS-RunShellScript with Operation Patch
AWS-UpdateSSMAgent
AWS-PatchOnly
The subnet ID
The patch group tag
The key pair name
The security group description
37. How do maintenance window duration and cutoff work?
The duration is how long the window stays open, from 1 to 24 hours. The cutoff is how many hours before the end Systems Manager stops starting new tasks, from 0 to 23.
Example: a 4-hour window with a 1-hour cutoff accepts new tasks for the first 3 hours. Tasks that were already running when the cutoff arrives are allowed to continue until the window closes.
Set the cutoff longer than your slowest task so nothing begins that cannot finish inside the allowed period.
Take quiz
1 hour
4 hours
3 hours
5 hours
Targets from registering
The window from running again
Tasks from using Run Command
New tasks starting too close to the end
38. When would you choose a maintenance window over a State Manager association?
Choose a maintenance window when the work is disruptive, needs ordering, and must stay inside an approved time slot - patching with reboots, database upgrades, restarts of production services.
Choose a State Manager association when the action is safe to repeat and should keep running, such as updating the SSM Agent, ensuring software is installed, or gathering inventory.
Windows also give you task priority, multiple task types (including Lambda and Step Functions), and the cutoff safety net, which associations do not offer. Associations are simpler and also apply to newly launched matching nodes automatically.
Take quiz
Maintenance window
State Manager inventory association
OpsCenter OpsItem
Parameter policy
Maintenance window with priority 1
State Manager association
Session Manager preferences
Fleet Manager
39. Explain the execution flow of an Automation runbook?
When you start an Automation, Systems Manager creates an execution, assumes the AutomationAssumeRole and processes steps in order from the runbook's mainSteps.
Each step calls its action - an AWS API, a Run Command, a script, an approval - waits for the result, optionally validates it, then moves to the next step. A step can branch with aws:branch, pause for approval, or fail, in which case onFailure decides whether to abort, continue, or jump to another step.
flowchart TD
A["Start execution"] --> B["Assume AutomationAssumeRole"]
B --> C["Run step 1"]
C --> D{Succeeded?}
D -- Yes --> E["Next step"]
D -- No --> F["onFailure: abort, continue or step"]
E --> G["Execution complete"]
Step-level status and outputs are visible in the execution detail page.
Take quiz
The EC2 instance profile only
The caller's root account
The AutomationAssumeRole
The CloudTrail service role
The document name
The target tag
The KMS key policy
The step's onFailure setting
40. What are common Automation actions used in runbooks?
Most runbooks combine a small set of actions.
| Action | Purpose |
| aws:executeAwsApi | Call any AWS API and capture output |
| aws:runCommand | Run a Command document on instances |
| aws:executeScript | Run Python or Node.js code inline |
| aws:changeInstanceState | Start, stop or terminate instances |
| aws:createImage | Create an AMI from an instance |
| aws:waitForAwsResourceProperty | Wait until a resource reaches a state |
| aws:branch | Choose the next step based on a condition |
| aws:approve | Pause until approvers respond |
You chain these with outputs from earlier steps, for example {{ createStep.ImageId }}, to build workflows like stop - snapshot - patch - start.
Take quiz
aws:executeAwsApi
aws:runCommand
aws:sleep
aws:approve
aws:createImage
aws:waitForAwsResourceProperty
aws:branch
aws:executeScript
41. How do you add manual approval to an Automation runbook?
Add an aws:approve step before the risky action. The execution pauses at that step until the required approvers approve or deny, or until a timeout expires.
- name: approveRestart action: aws:approve timeoutSeconds: 3600 inputs: NotificationArn: arn:aws:sns:us-east-1:111122223333:ops-approvals Message: Approve production restart? MinRequiredApprovals: 1 Approvers: - arn:aws:iam::111122223333:role/OpsLead
An SNS notification tells approvers a decision is waiting. If anyone denies, the execution stops as failed. For formal change control across the organization, Change Manager adds templates and approval workflows on top of Automation.
Take quiz
The step is skipped silently
The runbook retries forever
The execution stops as failed
The approver's role is deleted
Through an SSH banner
Through an EBS snapshot
Through a VPC route
Through an SNS notification
42. What happens when an Automation step fails?
The step's failure handling properties decide the outcome.
maxAttemptsretries the step before it is marked failed.timeoutSecondsfails a step that runs too long.onFailurecan beAbort(default),Continue, orstep:stepNameto jump to a cleanup or rollback step.isCritical: falselets the overall execution succeed even when that step fails.
A good runbook uses onFailure to jump to a rollback step, for example restoring from the AMI it created, instead of leaving resources half-changed.
Take quiz
step:stepName
Retry:all
Goto:end
Rollback:auto
Limits how many runbooks exist
Retries the step before marking it failed
Caps the AWS account's API calls
Limits parameter size
43. How can Automation run across multiple accounts and Regions?
Automation supports multi-account and multi-Region executions through TargetLocations. You list account IDs (or organizational units) and Regions, and Systems Manager runs the runbook in each location.
In every target account, the execution assumes the role named by ExecutionRoleName, which must trust the administrator account's Automation role. Rate controls like MaxConcurrency and MaxErrors keep the rollout gradual.
aws ssm start-automation-execution --document-name MyRunbook \ --target-locations "Accounts=111122223333,444455556666,Regions=us-east-1,eu-west-1,ExecutionRoleName=AutomationExecRole"
This is how organizations run remediation or AMI cleanup fleet-wide from one place.
Take quiz
TargetNodes
RegionMap
TargetLocations
OrgTargets
The root user
The EC2 instance profile
The SSM service-linked role of the target
The role named by ExecutionRoleName
44. How do you troubleshoot an instance that does not appear as a managed node?
Work through the three requirements in order.
- Agent - confirm SSM Agent is installed and running, and check
/var/log/amazon/ssm/amazon-ssm-agent.logfor errors. - IAM - verify an instance profile with
AmazonSSMManagedInstanceCore(or Default Host Management Configuration) is attached. - Network - make sure outbound 443 reaches the
ssm,ssmmessagesandec2messagesendpoints, through internet, NAT or VPC endpoints. - Time and region - check the system clock is correct and the console Region matches the instance.
The Systems Manager Automation runbook AWSSupport-TroubleshootManagedInstance automates several of these checks.
Take quiz
That SSM Agent is installed and running
That port 22 is open
That a public IP exists
That EBS is encrypted
Register normally using a hidden route
Fail to register because it cannot reach SSM
Register only for Fleet Manager
Register but only for Patch Manager
45. How do you use Systems Manager in a private VPC without internet access?
Create interface VPC endpoints so the SSM Agent can reach the service privately.
| Endpoint | Needed for |
| com.amazonaws.region.ssm | Core Systems Manager API |
| com.amazonaws.region.ssmmessages | Session Manager and agent messaging |
| com.amazonaws.region.ec2messages | Run Command message delivery |
| com.amazonaws.region.s3 (gateway) | Patch, document and log object access |
| com.amazonaws.region.logs / kms | Optional, for log streaming and encryption |
Enable private DNS on the endpoints and allow inbound 443 from the instances in the endpoint security group. Without S3 access some features, such as patching Amazon Linux repositories, will fail even if the agent registers.
Take quiz
sts
ecr.dkr
ec2messages
sqs
Inbound 22 from the internet
Outbound 25 only
All inbound UDP
Inbound 443 from the instances
46. What is Default Host Management Configuration and why use it?
Default Host Management Configuration (DHMC) lets Systems Manager manage your EC2 instances without attaching an instance profile to each one. You turn it on per account and Region, and Systems Manager uses the role AWSSystemsManagerDefaultEC2InstanceManagementRole to give instances baseline permissions.
It reduces setup friction, since you no longer need to remember to add AmazonSSMManagedInstanceCore to every role. If an instance does have its own profile, the profile's permissions take precedence.
It requires IMDSv2 and a recent SSM Agent, and it only covers EC2 instances, not hybrid nodes.
Take quiz
Attaching an SSM instance profile to every instance
Running the SSM Agent
Opening port 443
Creating a VPC
On-premises servers
EC2 instances only
Edge devices only
Any container image
47. How do you manage on-premises servers with Systems Manager?
Register them as hybrid managed nodes.
- Create an IAM service role that Systems Manager can assume for the nodes.
- Create a hybrid activation and note the activation code and ID.
- Install SSM Agent on each server and register it with the code, ID and Region.
- Confirm the nodes appear in Fleet Manager with
mi-IDs.
flowchart LR A["IAM service role"] --> B["Create hybrid activation"] B --> C["Install SSM Agent on server"] C --> D["Register with code and ID"] D --> E["Managed node mi-xxxx"]
Standard tier covers up to 1,000 hybrid nodes per account and Region. Beyond that, or to use Session Manager on non-EC2 nodes, you need the advanced-instances tier.
Take quiz
i- prefixed IDs
vm- prefixed IDs
mi- prefixed IDs
ami- prefixed IDs
A Direct Connect circuit
A dedicated bastion
An Elastic IP per server
The advanced-instances tier
48. How does Inventory with Resource Data Sync help analysis?
Inventory data lives per node in Systems Manager, which makes fleet-wide questions awkward. A resource data sync continuously copies the inventory from all your nodes, accounts and Regions into one S3 bucket.
From there you can query it with Athena and build dashboards in QuickSight. Questions like "which servers still run OpenSSL 1.0?" or "which instances lack the monitoring agent?" become simple SQL queries.
For organizations, the sync can aggregate data from every account in AWS Organizations. The bucket needs a policy allowing Systems Manager to write to it, and you can encrypt the data with KMS.
Take quiz
In an S3 bucket
In CloudFront
In an RDS snapshot
In Route 53
AWS Glue DataBrew only
Amazon Athena
Amazon Rekognition
AWS Snowball
49. How do you secure Systems Manager with least-privilege IAM?
Scope what people and roles can do, and which resources they can touch.
- Grant
ssm:StartSessiononly on specific instances or by tag, using the conditionssm:resourceTag/Env. - Limit
ssm:SendCommandto chosen documents, such as read-only diagnostics. - Restrict parameter access by path, for example
parameter/shop/prod/*. - Control SecureString decryption with a KMS key policy.
- Use Session Manager preferences to enforce logging, encryption and idle timeouts.
Pair this with CloudTrail so every API call is auditable. Avoid giving the instance profile broad S3 or admin rights just because SSM runs on it.
Take quiz
aws:SourceVpc
ssm:AssumeRoleTag
ssm:resourceTag
ec2:InstanceTypeFilter
Block port 22
Disable CloudTrail
Remove the SSM Agent
Restrict ssm:SendCommand to specific document ARNs
50. How can you use Parameter Store values in CloudFormation, ECS and Lambda?
Each service has a native way to read parameters, so values stay out of templates and code.
- CloudFormation - use a dynamic reference such as
{{resolve:ssm:/shop/prod/db/host}}, or a parameter of typeAWS::SSM::Parameter::Value<String>. - ECS - map a parameter to a container environment variable in the task definition using
secretswith the parameter ARN. - Lambda - call
GetParameterin code, cache the result outside the handler, or use the Parameters and Secrets Lambda extension.
Parameters: AmiId: Type: AWS::SSM::Parameter::Value<AWS::EC2::Image::Id> Default: /aws/service/ami-amazon-linux-latest/al2023-ami-kernel-default-x86_64
The task or function role needs ssm:GetParameter and, for SecureString, kms:Decrypt.