An organization manages hundreds of AWS accounts using AWS Organizations. A solutions architect needs to implement baseline protection against the OWASP Top 10 web application vulnerabilities using AWS WAF for all current and future Amazon CloudFront distributions in the organization. Which combination of actions should the solutions architect take to provide that baseline protection? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Enable AWS Config in all accounts in the organization., Enable all features for the AWS Organization (enable trusted access and organization-wide features)., Use AWS Firewall Manager to deploy AWS WAF rules across all accounts for all CloudFront distributions..
Why this is the answer
To centrally manage and deploy AWS WAF rules across multiple accounts for CloudFront distributions, AWS Firewall Manager is the correct service. Firewall Manager requires AWS Organizations to be fully enabled, including trusted access and all features, to function across the organization. AWS Config must also be enabled in all member accounts for Firewall Manager to monitor resource compliance and detect out-of-scope resources. GuardDuty, Shield Advanced, and Security Hub are security services that offer different protections (threat detection, DDoS protection, and security posture management, respectively) but do not directly deploy or manage WAF rules across an organization in the way Firewall Manager does.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed