A company wants to centrally define and enforce Amazon VPC security group policies across multiple AWS accounts in an organization under AWS Organizations. Which AWS service enables this centralized management?
Choose an answer
Tap an option to check your answer.
Correct answer: AWS Firewall Manager.
Why this is the answer
AWS Firewall Manager is the correct choice because it allows you to centrally configure and manage firewall rules across your accounts and applications in AWS Organizations. This includes centrally defining and enforcing Amazon VPC security group policies, ensuring consistent security posture. Amazon GuardDuty is a threat detection service, not for policy enforcement. Amazon Detective helps investigate security findings, not manage policies. AWS WAF (Web Application Firewall) protects web applications from common exploits, but doesn't manage VPC security groups across accounts.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed