A company has VPCs across 50 AWS accounts in an AWS Organization and needs to implement consistent web filtering using AWS Network Firewall. The filtering requirements are the same for all VPCs. The network engineer wants to minimize how many firewall policies and rule groups must be created. Which combination of steps will meet these requirements? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create a firewall policy or rule group in the management account., Use AWS Resource Access Manager (AWS RAM) to share the firewall policy or rule group., Enable sharing within AWS Organizations..
Why this is the answer
To centralize management and minimize duplication, the firewall policy or rule group should be created once in a central account, such as the management account. AWS Resource Access Manager (RAM) is the service used to share resources, including Network Firewall policies and rule groups, across AWS accounts within an organization. For RAM sharing to function correctly within an AWS Organization, sharing with AWS Organizations must be enabled. Creating a firewall policy or rule group in each account would lead to unnecessary duplication. SCPs are used for permissions management, not resource sharing. OUs organize accounts but don't directly facilitate resource sharing.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed