Courseiva
Network Security, Compliance and GovernancehardMultiple ChoiceObjective-mapped

ANS-C01 Network Security, Compliance and Governance Practice Question

A company wants to centrally manage and enforce VPC security group rules across multiple accounts in AWS Organizations. Which AWS service should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Firewall Manager

AWS Firewall Manager is the correct service for centrally managing and enforcing VPC security group rules across multiple accounts in AWS Organizations. It provides centralized security policy management, allowing you to define common security group rules and automatically apply them to new and existing accounts. AWS Config (Option A) is primarily for compliance auditing and resource configuration history, not enforcement. AWS CloudFormation StackSets (Option B) can deploy resources across accounts but does not provide ongoing enforcement of security policies. IAM Policies (Option D) control permissions, not security group configurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Config

    Why it's wrong here

    AWS Config is used for compliance auditing and configuration tracking, but it cannot enforce security group rules across accounts.

  • AWS CloudFormation StackSets

    Why it's wrong here

    AWS CloudFormation StackSets can deploy resources like security groups, but it does not provide ongoing central management or enforcement of rules.

  • AWS Firewall Manager

    Why this is correct

    AWS Firewall Manager allows central creation and enforcement of security group rules across all accounts in an organization, making it the correct choice.

  • IAM Policies

    Why it's wrong here

    IAM Policies manage user permissions and cannot directly configure or enforce security group rules.

About these practice questions

This ANS-C01 question is part of Courseiva's 1,621-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on ANS-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company wants to centrally manage and enforce security rules for all VPCs in a multi-account environment. Which AWS service should be used?

easy
  • A.Amazon GuardDuty
  • B.AWS Shield
  • C.AWS Firewall Manager
  • D.AWS WAF

Why C: AWS Firewall Manager is the correct choice because it provides centralized management of firewall rules across multiple accounts and VPCs in an AWS Organization. It allows you to enforce a common set of security policies, such as AWS WAF rules, AWS Shield Advanced protections, and VPC security group rules, ensuring consistent governance across all VPCs in the multi-account environment.

Variation 2. Which AWS service can be used to centrally manage and enforce security group rules across multiple accounts in AWS Organizations?

easy
  • A.AWS Identity and Access Management (IAM)
  • B.AWS Firewall Manager
  • C.AWS Config
  • D.AWS Shield Advanced

Why B: AWS Firewall Manager (Option B) is the correct answer because it provides centralized management of security group rules across accounts in AWS Organizations, allowing you to enforce a common set of security rules. Option A (IAM) manages user permissions, not security groups. Option C (AWS Config) evaluates resource compliance but does not enforce rules. Option D (AWS Shield Advanced) is a DDoS protection service.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.