AWS Certified Advanced Networking – Specialty (ANS-C01)Network Management and OperationsHard

A large enterprise uses AWS Organizations to manage multiple AWS accounts across different business units. Each business unit has its own VPCs and applications. The central networking team needs to enforce a consistent set of network security group rules across all newly created EC2 instances in all accounts. They want to automate this enforcement and ensure compliance, preventing individual teams from deviating from the standard. Which AWS service combination can achieve this goal most efficiently and scalably?

  1. AAWS Firewall Manager and AWS Organizations
  2. BAWS Organizations Service Control Policies (SCPs) and AWS Lambda
  3. CAWS Resource Access Manager (RAM) and AWS Service Catalog
  4. DAWS Systems Manager State Manager and AWS Config
Show answer & explanation

Correct answer: A. AWS Firewall Manager and AWS Organizations

AWS Firewall Manager allows central management and enforcement of security policies (like WAF rules, Shield Advanced, VPC security groups, and Network ACLs) across multiple accounts and resources in AWS Organizations. It can automatically apply a common set of security group rules to newly created EC2 instances or even audit existing ones for compliance, making it the most efficient and scalable solution for this requirement.

Why the other options are wrong

  • B. SCPs restrict actions but don't configure resources like security groups. AWS Lambda could be used for automation, but combining it with SCPs for this specific task would be less direct and scalable than Firewall Manager.
  • C. AWS Resource Access Manager shares resources, and Service Catalog allows creating and managing approved IT services, but neither directly enforces security group rules across newly launched instances in a centralized, automated manner.
  • D. Systems Manager State Manager can maintain desired configurations, but integrating it across multiple accounts for security groups and ensuring new instance compliance is more complex than Firewall Manager. AWS Config audits compliance but doesn't enforce proactive remediation in this way.

AWS Firewall Manager

A security management service that allows you to centrally configure and manage firewall rules across your accounts and applications in AWS Organizations.

  • Centralized security policy management
  • Applies policies across multiple accounts
  • Supports WAF, Shield Advanced, Security Groups, Network ACLs

Memory trick: Firewall Manager: The organization's security guard, enforcing rules everywhere.

More Network Management and Operations questions