SCS-C02 Infrastructure Security Practice Question
A company has a multi-account AWS environment using AWS Organizations. The security team wants to centrally manage VPC security group rules across all accounts. Which AWS service should they use?
⚠ Common exam trap
SCS-C02 often tests the distinction between services that can audit security groups (AWS Config) and those that can centrally manage and enforce rules (AWS Firewall Manager). Candidates frequently confuse AWS Config's compliance checks with actual enforcement capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Firewall Manager
AWS Firewall Manager is designed to centrally manage security policies across all accounts in an AWS Organization, including VPC security group rules. It allows you to define a security group policy that automatically applies to existing and new resources, ensuring consistent enforcement across the organization. This is the only service among the options that provides centralized, cross-account management of security groups.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Network Firewall
Why it's wrong here
AWS Network Firewall is a managed firewall service that provides stateful and stateless packet filtering, intrusion prevention, and network traffic inspection for VPCs using firewall policies and rule groups. While it can be centrally deployed via AWS Firewall Manager, the service itself does not manage or enforce VPC security group rules; security group rules and firewall policies are separate artifacts controlling different layers of network traffic. Thus it is not the correct tool for centrally managing security group rules across an organization.
- ✓
AWS Firewall Manager
Why this is correct
AWS Firewall Manager is the designated service for centrally managing VPC security group rules across all accounts and resources within an AWS Organization. It allows administrators to create security group policies, enforce common security group rules, remediate noncompliant rules automatically, and apply consistent protection to new accounts as they join the organization. This directly matches the requirement for central management of security group rules, making it the correct answer.
- ✗
AWS Config
Why it's wrong here
AWS Config is a service for recording, auditing, and evaluating configuration changes of individual AWS resources using rules and remediation actions. It can detect noncompliant security group rules, such as overly permissive ingress, but it does not provide a mechanism to centrally author, deploy, or enforce security group rules across multiple accounts. Its role is governance and change monitoring, not active centralized management of VPC security group policies.
- ✗
Amazon Route 53 Resolver DNS Firewall
Why it's wrong here
Amazon Route 53 Resolver DNS Firewall is a DNS-level security service that filters outbound DNS queries and responses based on domain lists at the VPC resolver level. It blocks traffic by controlling which domain names can be resolved, such as preventing communication with known malicious domains, but it operates entirely at Layer 7 for DNS and has no ability to define or manage VPC security group rules. Therefore, it does not address central management of security group rules across accounts.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.