Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

Which AWS service can be used to centrally manage VPC security groups and network ACLs across multiple accounts in AWS Organizations?

⚠ Common exam trap

Many candidates confuse AWS Firewall Manager with AWS WAF or AWS Shield, assuming any 'firewall' or 'security' service can manage VPC-level constructs, but only Firewall Manager provides centralized cross-account management of security groups and NACLs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Firewall Manager

AWS Firewall Manager is the correct service because it provides centralized management of security groups and network ACLs across multiple accounts within AWS Organizations. It allows you to define common security rules and apply them automatically to new and existing accounts, ensuring consistent enforcement of VPC security policies without manual per-account configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Firewall Manager

    Why this is correct

    AWS Firewall Manager is the service designed to centrally configure and administer VPC security rules across accounts in an AWS Organization. It lets you create security group policies and network ACL policies that are automatically applied to new and existing VPC resources, enforcing a consistent security posture. This central management capability directly matches the scenario of managing VPC security centrally.

  • ✗

    AWS Shield

    Why it's wrong here

    AWS Shield is a managed distributed denial-of-service (DDoS) protection service that safeguards applications running on AWS. It does not create or manage security groups or network ACLs; instead it operates at the network/edge layer to absorb and mitigate volumetric attacks. While Shield can be used alongside Firewall Manager, it is not a tool for centrally managing VPC security configurations.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a service that records resource configuration changes and evaluates them against rules for compliance auditing. It can detect security group or NACL changes and even trigger auto-remediation via Systems Manager, but it is not a central management console for proactively defining and pushing those policies across accounts. Its role is detective/compliance, not administrative enforcement of VPC security policies.

  • ✗

    AWS WAF

    Why it's wrong here

    AWS WAF is a web application firewall that filters and monitors HTTP(S) traffic based on rules such as IP reputation, SQL injection, or cross-site scripting. It operates at layer 7 on Application Load Balancers, CloudFront, or API Gateway, and does not manage VPC-level security groups or network ACLs. WAF is complementary security, but it is not the correct service for centrally managing VPC security rules.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.