AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceMedium
A large enterprise with a multi-account AWS environment needs to centrally manage network access control for all VPCs. The security team wants to define a set of common egress filtering rules (e.g., blocking access to known malicious IPs, allowing access only to specific SaaS endpoints) and ensure these rules are automatically applied to new and existing VPCs across all accounts. Which AWS service is designed to achieve this centralized, automated management of network perimeter security?
- AAWS Organizations Service Control Policies (SCPs)
- BAWS Network Firewall
- CAWS Transit Gateway
- DAWS Firewall Manager
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Firewall Manager
AWS Firewall Manager is specifically designed to centrally configure and manage firewall rules across multiple AWS accounts and VPCs in an organization. It can automatically apply and enforce common security policies, including AWS WAF rules, AWS Shield Advanced, and AWS Network Firewall policies, ensuring consistent perimeter security.
Why the other options are wrong
- A. SCPs define maximum permissions for accounts and can prevent certain actions, but they don't directly manage or automatically deploy network filtering rules like blocking malicious IPs or allowing specific SaaS endpoints.
- B. AWS Network Firewall provides stateful inspection for individual VPCs but doesn't offer centralized management across accounts for automatic deployment.
- C. AWS Transit Gateway facilitates centralized routing between VPCs and on-premises networks but does not provide centralized firewall rule management and automated policy application.
AWS Firewall Manager
A security management service that allows you to centrally configure and manage firewall rules across your accounts and applications in AWS Organizations.
- Centrally manages AWS WAF, AWS Shield Advanced, AWS Network Firewall, and Security Groups.
- Automatically applies security policies to new and existing resources.
- Enforces consistent security across multiple accounts and VPCs.
- Simplifies compliance by ensuring policies are uniformly applied.
Memory trick: Firewall Manager organizes rules for all accounts, auto-applying.