Courseiva
Network Security, Compliance and GovernancemediumMultiple SelectObjective-mapped

Centralized Security Policy Management with SCPs and Firewall Manager

A company is designing a network security architecture for a multi-account environment using AWS Organizations. Which TWO services can be used to centrally manage security policies across all accounts?

Quick Answer

The answer is AWS Firewall Manager and AWS Organizations Service Control Policies (SCPs). AWS Firewall Manager provides centralized security policy management by allowing you to apply AWS WAF rules, AWS Shield Advanced protections, and security group policies across all accounts in your AWS Organization from a single administrative account, ensuring consistent enforcement without per-account configuration. SCPs complement this by centrally controlling the maximum permissions available to member accounts, effectively acting as a guardrail for what services and actions are allowed. On the AWS Certified Advanced Networking Specialty ANS-C01 exam, this pairing tests your understanding of how to separate network-level security enforcement (Firewall Manager) from identity-based permission boundaries (SCPs) in a multi-account architecture. A common trap is confusing AWS Config or CloudTrail, which are per-account audit tools, with centralized policy enforcement services. Memory tip: think of Firewall Manager as the "shield" for network rules and SCPs as the "fence" for account permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Organizations Service Control Policies (SCPs)

AWS Firewall Manager provides centralized management of firewall rules (including AWS WAF, AWS Shield Advanced, and security groups) across all accounts in AWS Organizations. AWS Organizations Service Control Policies (SCPs) allow you to centrally define and enforce permission boundaries and security policies across all member accounts. In contrast, AWS Config and AWS CloudTrail operate per account and do not provide centralized policy management across multiple accounts. Amazon VPC is a per-account networking service. Therefore, the correct answers are C (SCPs) and D (Firewall Manager).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Config

    Why it's wrong here

    AWS Config is per-account, not central.

  • AWS CloudTrail

    Why it's wrong here

    CloudTrail is per-account.

  • AWS Organizations Service Control Policies (SCPs)

    Why this is correct

    SCPs centrally control permissions across accounts.

  • AWS Firewall Manager

    Why this is correct

    Firewall Manager centrally manages firewall rules across accounts.

  • Amazon VPC

    Why it's wrong here

    VPC is per-account.

About these practice questions

Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on ANS-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company is designing a network security architecture for a multi-account environment using AWS Organizations. They need to centrally manage and enforce security policies across all accounts. Which THREE services should they consider?

hard
  • A.AWS Direct Connect
  • B.AWS Firewall Manager
  • C.AWS Security Hub
  • D.Amazon Route 53 Resolver DNS Firewall
  • E.AWS CloudTrail

Why B: Options B, C, and E are correct: AWS Firewall Manager centrally manages firewall rules across accounts; AWS Security Hub provides a unified view of security alerts and compliance checks; AWS CloudTrail logs API calls across accounts for auditing and monitoring. Option A is wrong because AWS Direct Connect is a dedicated network connection service, not a policy enforcement service. Option D is wrong because Amazon Route 53 Resolver DNS Firewall is a DNS-layer filtering service, but the question asks for central policy enforcement and management across accounts, which is not its primary function.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.