AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceMedium
A large enterprise has a multi-account AWS environment with hundreds of VPCs across several regions. They need to enforce a consistent set of security policies, including WAF rules, Shield Advanced protections, and custom Firewall Manager policies, across all their web applications and underlying resources. This must be managed centrally by the security team without manual configuration in each account or VPC. Which AWS service provides this centralized, automated policy enforcement?
- AAWS Config
- BAWS Firewall Manager
- CAWS Organizations
- DAWS Security Hub
Show answer & explanationAnswer & explanation
Correct answer: B. AWS Firewall Manager
AWS Firewall Manager is specifically designed to centrally configure and manage firewall rules across multiple AWS accounts and VPCs in an AWS Organization. It can deploy and manage AWS WAF rules, AWS Shield Advanced protections, and Network Firewall policies, ensuring consistent security posture.
Why the other options are wrong
- A. AWS Config monitors and records AWS resource configurations and changes but does not enforce security policies in an active manner like a firewall manager.
- C. AWS Organizations allows for centralized account management and consolidated billing but does not directly enforce security policies like WAF or Shield rules.
- D. AWS Security Hub aggregates security findings and performs security checks but does not enforce or deploy security policies across accounts.
AWS Firewall Manager
A security management service that allows you to centrally configure and manage firewall rules across your accounts and applications in AWS Organizations.
- Centralized management for WAF, Shield Advanced, Network Firewall.
- Applies policies across multiple accounts and VPCs.
- Automates deployment and ensures compliance.
- Requires AWS Organizations.
Memory trick: Firewall Manager is the 'orchestra conductor' for all security rules in your AWS Organization.