A company has more than 50 AWS accounts across five Regions and wants simplified centralized security management using AWS Firewall Manager. The organization in AWS Organizations is created with all features enabled. Which combination of next steps should the company take to meet the requirement to manage firewall rules across all accounts? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Add all member accounts to the organization., Designate one account as the Firewall Manager administrator account., Enable AWS Config for every account and for every Region where the company has resources..
Why this is the answer
To use AWS Firewall Manager for centralized security management across multiple accounts, all accounts must be part of the AWS Organization. This allows Firewall Manager to deploy and manage rules consistently. Designating a Firewall Manager administrator account is a prerequisite, as this account centrally manages the security policies for the organization. Finally, Firewall Manager relies on AWS Config to detect non-compliant resources and apply policies. Therefore, AWS Config must be enabled in every account and every Region where resources are to be managed by Firewall Manager. Configuring only the administrator account to join the organization is insufficient as Firewall Manager needs to manage all accounts. Marking an account as a Firewall Manager child account is not a standard configuration step; accounts are simply members of the organization. Enabling AWS Config only for the management account would prevent Firewall Manager from detecting resources in other accounts.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed