AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium
A company manages dozens of AWS accounts using AWS Organizations and wants to centrally deploy and enforce AWS WAF rules and Shield Advanced protections consistently across all accounts and resources, rather than configuring each account individually. Which AWS service is designed for this purpose?
- AAmazon Inspector
- BAWS Config aggregator
- CAWS Trusted Advisor
- DAWS Firewall Manager
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Firewall Manager
AWS Firewall Manager allows central configuration and management of firewall rules, including AWS WAF rules, AWS Shield Advanced protections, and security groups, across multiple accounts within an AWS Organization. Amazon Inspector focuses on vulnerability scanning, AWS Config aggregators consolidate configuration data (not enforce firewall rules), and Trusted Advisor provides best-practice checks but does not centrally deploy WAF/Shield policies.
Why the other options are wrong
- A. Inspector scans for vulnerabilities in EC2/ECR/Lambda, not firewall rule management.
- B. Config aggregators consolidate compliance data but don't enforce firewall policies.
- C. Trusted Advisor gives recommendations, not centralized policy enforcement.
AWS Firewall Manager
A security management service that centrally configures and enforces AWS WAF rules, Shield Advanced protections, and security groups across multiple accounts in an AWS Organization.
- Requires AWS Organizations
- Centralizes WAF, Shield Advanced, and security group policies
- Automatically applies policies to new accounts/resources
Memory trick: Firewall Manager = one firewall policy ruling many accounts