AWS Certified CloudOps Engineer - Associate

Patch and State Management

Keep a fleet patched and stop it drifting: Scan versus Install, patch baseline approval rules and their 7-day default, how patch groups pick a baseline, the compliance states and the reboot option that produces them, maintenance windows with duration and cutoff, patch policies, and State Manager associations.

Advanced 32 minutes 7 Learning Objectives
  1. Distinguish a Scan operation from an Install operation and predict the compliance data each produces
  2. Read a patch baseline's approval rules, including auto-approval delay, approve-until date, and the two rejected patches actions
  3. Trace which patch baseline a node uses from its Patch Group tag, including the two cases that fall back to the default baseline
  4. Map each patch compliance state to its cause, and explain how the RebootOption parameter produces InstalledPendingReboot
  5. Configure a maintenance window with a duration, a cutoff, task priorities, and rate control, and predict what happens at cutoff
  6. Choose between a patch policy, a maintenance window, and a State Manager association for a given patching or configuration requirement
  7. Explain what a State Manager association enforces and why it applies itself to newly launched instances