Courseiva
Security and Compliance →hardMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company has an AWS account with multiple VPCs connected via a transit gateway. The security team wants to centrally manage VPC security group rules and ensure compliance. Which approach is most effective?

⚠ Common exam trap

Many exam-takers think CloudFormation or a single security group can achieve centralized management, but they overlook the cross-VPC scope limitation of security groups and the lack of automated enforcement and compliance monitoring in those approaches.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Firewall Manager to centrally define and enforce security group rules across all VPCs.

AWS Firewall Manager is the correct choice because it provides centralized administration of security group rules across multiple VPCs and accounts, enabling the security team to define a common set of rules and automatically enforce compliance. It integrates with AWS Organizations to apply policies to all VPCs in the organization, ensuring consistent security posture without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use AWS Firewall Manager to centrally define and enforce security group rules across all VPCs.

    Why this is correct

    AWS Firewall Manager is the correct choice because it provides centrally managed security policies that automatically apply and enforce security group rules across all VPCs and accounts in an AWS Organization. It continuously audits compliance, automatically repairs non-compliant resources, and allows you to define common security group rules in one place, eliminating per-VPC manual updates while offering a single pane of glass for ongoing enforcement.

  • ✗

    Create a single security group and attach it to all VPCs.

    Why it's wrong here

    A security group is a VPC-scoped resource; each security group exists only within the VPC where it was created and cannot be attached to instances in a different VPC. Even with VPC peering or a transit gateway, you cannot reference or share a security group across VPC boundaries, so creating a single security group and attaching it to all VPCs is fundamentally impossible—you would need a separate security group in each VPC.

  • ✗

    Define security group rules in AWS CloudFormation templates and deploy them to each VPC.

    Why it's wrong here

    CloudFormation templates can deploy security group rules consistently across many VPCs via StackSets, but this is a provisioning mechanism, not ongoing centralized enforcement. Once deployed, changes to the template require a deliberate update action, and without additional services like AWS Config to detect drift, non-compliant changes made outside CloudFormation will go unnoticed. It lacks the continuous auditing and automatic remediation that Firewall Manager provides, making it a manual, not centralized, solution.

  • ✗

    Use network ACLs instead of security groups for centralized management.

    Why it's wrong here

    Network ACLs are stateless and operate at the subnet level, not at the VPC or instance level, which fundamentally changes traffic behavior compared to security groups. They require separate inbound and outbound rules, are evaluated in numeric order, and do not support stateful allow-return traffic, so using them instead of security groups would break common application patterns and create onerous rule management. Network ACLs also lack the VPC-scoped central management and instance-level control needed to replace security groups across multiple VPCs.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.