Courseiva
Infrastructure Security →hardMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company has a multi-account AWS environment using AWS Organizations. The security team wants to centrally manage VPC security group rules across all accounts. Which solution should be used?

⚠ Common exam trap

Test-takers frequently confuse AWS Config's detection and remediation capabilities with centralized enforcement, not realizing that Config operates per-account and lacks the multi-account policy management that Firewall Manager provides.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Firewall Manager to define security group policies and enforce them across accounts.

AWS Firewall Manager is the correct choice because it provides centralized management of security group rules across multiple accounts in an AWS Organization. It allows the security team to define a common security group policy and automatically enforce it across all member accounts, ensuring consistent security posture without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use AWS Firewall Manager to define security group policies and enforce them across accounts.

    Why this is correct

    AWS Firewall Manager is the correct service for centrally managing security group rules across all accounts in an AWS Organization. You can create a security group policy that defines baseline ingress/egress rules, and Firewall Manager automatically applies that policy to compliant and non-compliant resources in every member account, including new accounts added later. This is proactive enforcement, not just detection, and it also supports audit policies that continuously check and report security group drift.

  • ✗

    Use AWS Organizations Service Control Policies to restrict security group modifications.

    Why it's wrong here

    AWS Organizations Service Control Policies (SCPs) are IAM permission boundaries that restrict which API actions an account's principals can call. For example, an SCP could deny ec2:AuthorizeSecurityGroupIngress or ec2:RevokeSecurityGroupEgress, but it cannot create, update, or attach a security group to enforce a desired network configuration. SCPs operate in the control plane by limiting user permissions, not in the network data plane, so they cannot define the actual security group rules that Firewall Manager can enforce.

  • ✗

    Use AWS Config rules to automatically remediate non-compliant security groups.

    Why it's wrong here

    AWS Config rules are detective and reactive: they evaluate the configuration of your security groups against a desired state and can trigger a remediation action, such as an AWS Systems Manager Automation document, after a violation is detected. This introduces a delay between the non-compliant change and its correction, and it requires per-account or centrally deployed custom remediation logic. Firewall Manager instead prevents the non-compliant state from existing by actively managing the security group policy across all accounts before the drift can occur.

  • ✗

    Use AWS Network Firewall to inspect traffic and block unauthorized connections.

    Why it's wrong here

    AWS Network Firewall is a stateful, layer-3/4 packet-filtering service that sits at the VPC boundary and inspects actual network traffic at line rate; it does not manage security group rules. Security groups are virtual firewalls attached to ENIs or instances, and Network Firewall cannot add, remove, or update their ingress/egress rules. While it could block unauthorized connections as a data-plane defense, the requirement here is to define and enforce a security group configuration across accounts, which is a control-plane management task.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.