Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company has a multi-account AWS environment using AWS Organizations. The security team wants to centrally manage VPC security group rules across all accounts. Which AWS service should they use?

⚠ Common exam trap

SCS-C02 often tests the distinction between services that can audit security groups (AWS Config) and those that can centrally manage and enforce rules (AWS Firewall Manager). Candidates frequently confuse AWS Config's compliance checks with actual enforcement capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Firewall Manager

AWS Firewall Manager is designed to centrally manage security policies across all accounts in an AWS Organization, including VPC security group rules. It allows you to define a security group policy that automatically applies to existing and new resources, ensuring consistent enforcement across the organization. This is the only service among the options that provides centralized, cross-account management of security groups.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Network Firewall

    Why it's wrong here

    AWS Network Firewall is a managed firewall service that provides stateful and stateless packet filtering, intrusion prevention, and network traffic inspection for VPCs using firewall policies and rule groups. While it can be centrally deployed via AWS Firewall Manager, the service itself does not manage or enforce VPC security group rules; security group rules and firewall policies are separate artifacts controlling different layers of network traffic. Thus it is not the correct tool for centrally managing security group rules across an organization.

  • ✓

    AWS Firewall Manager

    Why this is correct

    AWS Firewall Manager is the designated service for centrally managing VPC security group rules across all accounts and resources within an AWS Organization. It allows administrators to create security group policies, enforce common security group rules, remediate noncompliant rules automatically, and apply consistent protection to new accounts as they join the organization. This directly matches the requirement for central management of security group rules, making it the correct answer.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a service for recording, auditing, and evaluating configuration changes of individual AWS resources using rules and remediation actions. It can detect noncompliant security group rules, such as overly permissive ingress, but it does not provide a mechanism to centrally author, deploy, or enforce security group rules across multiple accounts. Its role is governance and change monitoring, not active centralized management of VPC security group policies.

  • ✗

    Amazon Route 53 Resolver DNS Firewall

    Why it's wrong here

    Amazon Route 53 Resolver DNS Firewall is a DNS-level security service that filters outbound DNS queries and responses based on domain lists at the VPC resolver level. It blocks traffic by controlling which domain names can be resolved, such as preventing communication with known malicious domains, but it operates entirely at Layer 7 for DNS and has no ability to define or manage VPC security group rules. Therefore, it does not address central management of security group rules across accounts.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.