The security team requires that all internet-facing Application Load Balancers (ALBs) and Amazon API Gateway APIs have AWS WAF web ACLs. The organization has hundreds of AWS accounts in AWS Organizations and AWS Config is enabled. Some externally facing ALBs are not associated with WAF web ACLs. Which steps should the DevOps engineer take to prevent future violations? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Delegate AWS Firewall Manager to a centralized security account., Create an AWS Firewall Manager policy that attaches AWS WAF web ACLs to any newly created ALBs and API Gateway APIs..
Why this is the answer
To prevent future violations of the security policy, the DevOps engineer should leverage AWS Firewall Manager. First, delegating AWS Firewall Manager to a centralized security account allows for organization-wide security policy management across all AWS accounts. This is crucial for an organization with hundreds of accounts. Second, creating an AWS Firewall Manager policy that automatically attaches AWS WAF web ACLs to any newly created ALBs and API Gateway APIs ensures compliance from inception. This proactive approach prevents non-compliant resources from being deployed. Delegating Amazon GuardDuty is incorrect because GuardDuty is a threat detection service, not a policy enforcement or WAF management tool. Creating an Amazon GuardDuty policy is also incorrect for the same reason. Configuring an AWS Config managed rule is incorrect because while AWS Config can detect non-compliance, it cannot automatically attach WAF web ACLs to new resources across an entire organization in the same way Firewall Manager can.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed