CLF-C02 Security and Compliance Practice Question
A company manages 15 AWS accounts and wants to centrally deploy and enforce consistent AWS WAF rules, security groups, and Shield Advanced protections across all accounts and regions from a single administrator account. Which AWS service provides this centralised security policy management?
⚠ Common exam trap
Many exam-takers confuse AWS WAF (a resource-level protection service) with Firewall Manager (a multi-account policy management service), leading them to select AWS WAF instead of the centralized governance solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Firewall Manager
AWS Firewall Manager is the correct service because it provides centralized security policy management across multiple AWS accounts and regions. It allows an administrator to define and enforce AWS WAF rules, security group rules, and Shield Advanced protections from a single administrator account, ensuring consistent compliance across all accounts in an AWS Organization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS WAF
Why it's wrong here
AWS WAF is a web application firewall that enables you to create custom rules to block, allow, or monitor traffic destined for individual web resources within one account and one AWS Region. It operates at the resource level and has no native capability to enforce rules across multiple accounts or to apply consistent policies organization-wide. In the context of this question, WAF is the actual rule engine that Firewall Manager would centrally administer rather than a service that performs central management itself.
- ✗
AWS Security Hub
Why it's wrong here
AWS Security Hub aggregates security findings and compliance status from multiple AWS services into a unified, account-wide view. It helps you identify potential issues and assess overall security posture, but it does not have the ability to deploy or enforce WAF rules or any firewall policy. Its role is limited to detection and reporting, not centralized policy management or rule deployment across accounts.
- ✓
AWS Firewall Manager
Why this is correct
AWS Firewall Manager is the correct answer because it provides centralized security policy management within AWS Organizations, allowing you to deploy WAF rules, Shield Advanced protections, VPC security groups, and Network Firewall policies across all accounts and resources in a single action. Policies are automatically applied to new accounts or resources as they are added, ensuring consistent enforcement. This makes it the only service in the list that is purpose-built for centrally managing WAF rules across multi-account environments.
- ✗
AWS Shield Advanced
Why it's wrong here
AWS Shield Advanced is a managed DDoS protection service that safeguards specific resources, such as Amazon CloudFront distributions and Application Load Balancers, with enhanced detection and mitigation. While Firewall Manager can help deploy Shield Advanced protections as a policy, Shield Advanced itself cannot manage or enforce WAF rule sets. It is a single-service protection layer, not a centralized policy management tool for firewall or WAF rules.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CLF-C02 question from scratch — 993 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CLF-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses AWS Organizations to manage multiple accounts. The security team needs to enforce a policy that restricts SSH access (port 22) from the internet (0.0.0.0/0) in all VPCs across all accounts. The team wants to centrally define the allowed rules and automatically apply them to newly created VPCs and security groups, while also automatically remediating any existing non-compliant security groups. Which AWS service should the team use?
medium- A.AWS Config
- ✓ B.AWS Firewall Manager
- C.Amazon GuardDuty
- D.AWS Identity and Access Management (IAM)
Why B: AWS Firewall Manager is the correct service because it provides centralized management of firewall rules across all accounts in AWS Organizations. It can enforce a common security group rule to deny SSH access from 0.0.0.0/0, automatically apply this policy to new VPCs and security groups, and remediate non-compliant existing security groups by removing or replacing violating rules. This meets the requirement for both proactive enforcement and automated remediation at scale.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.