Subdomain 1.1: Implement metrics, alarms, and filters by using AWS monitoring and logging services.
1.An engineer is setting up the CloudWatch agent on a new EC2 instance for the first time and needs the instance to be able to push metrics and logs to CloudWatch and to retrieve its configuration from Systems Manager Parameter Store. Which two IAM actions should the engineer take?(Select 2)
- A.Attach the `CloudWatchAgentServerPolicy` managed policy to the instance's IAM role so the agent can publish metrics and logs to CloudWatch.
- B.Attach the `AmazonSSMManagedInstanceCore` managed policy to the same role so the instance can communicate with Systems Manager and retrieve stored parameters.
- C.Grant the instance's IAM role full `AdministratorAccess`, since the CloudWatch agent requires unrestricted permissions across every AWS service to start.
- D.Embed a long-term IAM access key directly inside the agent's JSON configuration file, since EC2 instance roles cannot supply credentials to the agent.
- E.Skip attaching any IAM role, since the CloudWatch agent authenticates using the instance's public IP address rather than AWS credentials.
- F.Create an IAM user with console access and share its password with the agent process, since only console users can publish custom metrics.
Show answer & explanation
Correct answers: A, B — Attach the `CloudWatchAgentServerPolicy` managed policy to the instance's IAM role so the agent can publish metrics and logs to CloudWatch.; Attach the `AmazonSSMManagedInstanceCore` managed policy to the same role so the instance can communicate with Systems Manager and retrieve stored parameters.
- A. Attaching `CloudWatchAgentServerPolicy` is correct because it grants exactly the permissions the agent needs to publish metrics and logs to CloudWatch from the instance.
- B. Attaching `AmazonSSMManagedInstanceCore` is correct because it lets the instance register with Systems Manager and read its stored configuration parameter from Parameter Store.
- C. Granting full `AdministratorAccess` is incorrect because it far exceeds the least-privilege permissions the agent needs and is not a requirement for the agent to start.
- D. Embedding a long-term access key is incorrect because instance roles do supply temporary credentials to the agent automatically, making a hardcoded key both unnecessary and a security risk.
- E. Skipping the IAM role is incorrect because the CloudWatch agent authenticates using AWS SDK credentials from the instance role, not the instance's public IP address.
- F. Sharing an IAM user's console password is incorrect because the agent uses programmatic credentials from an attached role, not interactive console login credentials.