GlobalBank operates 40 AWS accounts in AWS Organizations. The security team needs centralized enforcement so that: (1) all internet-facing ALBs have a standard AWS WAF web ACL, (2) organization-wide security group rules prevent 0.0.0.0/0 except on approved ports, and (3) Shield Advanced is enabled on internet-facing resources with DRT access. They want automatic application to new accounts and resources. What should they implement?
Choose an answer
Tap an option to check your answer.
Correct answer: Use AWS Firewall Manager with AWS Organizations to create WAF, security group, and Shield Advanced policies that auto-apply across the target OUs..
Why this is the answer
AWS Firewall Manager is the correct choice because it directly addresses all requirements for centralized, automatic enforcement across AWS Organizations. It allows security administrators to configure WAF web ACLs, security group rules, and Shield Advanced protection policies, and then automatically apply them to resources across multiple accounts and OUs. This ensures new accounts and resources are compliant from creation. Service Control Policies (SCPs) are for preventing actions that violate policies, not for enforcing specific configurations like WAF or Shield Advanced. AWS Config conformance packs detect non-compliance but do not automatically remediate or enforce policies. Amazon Inspector is a vulnerability management service, not a tool for enforcing WAF, security group rules, or Shield Advanced across an organization.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed