Which AWS service can be used to centrally manage VPC security groups and network ACLs across multiple accounts in AWS Organizations?
AWS Firewall Manager is the service designed to centrally configure and administer VPC security rules across accounts in an AWS Organization. It lets you create security group policies and network ACL policies that are automatically applied to new and existing VPC resources, enforcing a consistent security posture. This central management capability directly matches the scenario of managing VPC security centrally.
Why this answer
AWS Firewall Manager is the correct service because it provides centralized management of security groups and network ACLs across multiple accounts within AWS Organizations. It allows you to define common security rules and apply them automatically to new and existing accounts, ensuring consistent enforcement of VPC security policies without manual per-account configuration.
Exam trap
The trap here is that candidates confuse AWS Firewall Manager with AWS WAF or AWS Shield, assuming any 'firewall' or 'security' service can manage VPC-level constructs, but only Firewall Manager provides centralized cross-account management of security groups and NACLs.
How to eliminate wrong answers
Option B is wrong because AWS Shield is a managed Distributed Denial of Service (DDoS) protection service, not a tool for managing security groups or network ACLs. Option C is wrong because AWS Config is a service for evaluating and auditing resource compliance against rules, but it does not centrally manage or enforce security group or NACL policies across accounts. Option D is wrong because AWS WAF is a web application firewall that protects HTTP/HTTPS endpoints from common web exploits, and it does not manage VPC-level security groups or network ACLs.