What Is the Most Efficient Way to Manage AWS Network Firewall, WAF, and Security Groups?

A company is planning to host external websites on AWS. The websites will include multiple tiers such as web servers, application logic services, and databases. The company wants to use AWS Network Firewall, AWS WAF, and VPC security groups for network security. The company must ensure that the Network Firewall firewalls are deployed appropriately within relevant VPCs. The company needs the ability to centrally manage policies that are deployed to Network Firewall and AWS WAF rules. The company also needs to allow application teams to manage their own security groups while ensuring that the security groups do not allow overly permissive access. What is the MOST operationally efficient solution that meets these requirements?

  1. Define Network Firewall firewalls, AWS WAFV2 web ACLs. Network Firewall policies, and VPC security groups in code. Use AWS CloudFormation to deploy the objects and initial policies and rule groups. Use CloudFormation to update the AWS WAFv2 web ACLs. Network Firewall policies, and VPC security groups. Use Amazon GuardDuty to monitor for overly permissive rules.
  2. Define Network Firewall firewalls. AWS WAFV2 web ACLs, Network Firewall policies, and VPC security groups in code. Use the AWS Management Console or the AWS CLI to manage the AWS WAFv2 web ACLs. Network Firewall policies, and VPC security groups. Use Amazon GuardDuly to invoke an AWS Lambda function to evaluate the configured rules and remove any overly permissive rules.
  3. Deploy AWS WAFv2 IP sets and AWS WAFv2 web ACLs with AWS CloudFormation. Use AWS Firewall Manager to deploy Network Firewall firewalls and VPC security groups where required and to manage the AWS WAFv2 web ACLs, Network Firewall policies, and VPC security groups.
  4. Define Network Firewall firewalls, AWS WAFv2 web ACLS, Network Firewall policies, and VPC security groups in code. Use AWS CloudFarmation to deploy the objects and initial policies and rule groups. Use AWS Firewall Manager to manage the AWS WAFV2 web ACLS, Network Firewall policies, and VPC security groups. Use Amazon GuardDuty to monitor for overly permissive rules. Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your understanding that Firewall Manager is the central service for managing AWS WAF, Network Firewall, and security group policies across accounts, while CloudFormation handles the initial deployment.

This ANS-C01 question evaluates the best practice for centrally managing AWS Network Firewall, AWS WAF, and VPC security groups. The consensus answer is D, which combines CloudFormation for initial deployment, AWS Firewall Manager for centralized policy management, and GuardDuty for monitoring.

Choosing option A or B, which rely on CloudFormation or manual monitoring with GuardDuty to enforce overly permissive rules, instead of using AWS Firewall Manager for centralized and automated policy governance.

Community Discussion (4 comments)

AzureDP900 👍 3 Selected: D
The correct answer is indeed D. Define Network Firewall firewalls, AWS WAFv2 web ACLs, Network Firewall policies, and VPC security groups in code. Use AWS CloudFormation to deploy the objects and initial policies and rule groups. Use AWS Firewall Manager to manage the AWS WAFv2 web ACLs, Network Firewall policies, and VPC security groups. Use Amazon GuardDuty to monitor for overly permissive rules.
woorkim 👍 1
D is right! Option D is the most operationally efficient solution. It combines CloudFormation for consistent deployments, Firewall Manager for centralized policy management, and GuardDuty for monitoring and alerting on overly permissive rules
aragon_saa 👍 3 Selected: D
Answer is D
Cacheirez 👍 2 Selected: D
Firewall Manager makes it easier to centrally configure and manage AWS WAF, AWS Shield Advanced, and VPC security group policies across multiple accounts and applications in an AWS Organization. It also manages AWS Network Firewall policies.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option D is correct because it leverages AWS Firewall Manager to centrally manage AWS WAFv2 web ACLs, Network Firewall policies, and VPC security groups. Firewall Manager is designed to apply and enforce security policies across multiple accounts and VPCs within an AWS Organization, making it the most operationally efficient choice. CloudFormation is used to deploy the initial objects and policies, while GuardDuty provides monitoring for overly permissive rules, complementing Firewall Manager's automated governance.

Why the Other Options Are Wrong

Option A is incorrect because it uses CloudFormation to update policies and security groups, but CloudFormation does not provide centralized cross-account policy enforcement; GuardDuty only detects issues, it does not centrally manage policies. Option B is wrong because it relies on manual management via the console or CLI and uses a Lambda function to remove overly permissive rules, which is not as efficient or scalable as Firewall Manager. Option C is incomplete because it only deploys WAF IP sets and web ACLs with CloudFormation and uses Firewall Manager only for Network Firewall and security groups, missing the centralized management of WAFv2 web ACLs in the same manner as D.

Community Comment Notes

Comments on this question overwhelmingly support D, with votes at 100%. One comment notes that Firewall Manager makes it easier to centrally configure and manage AWS WAF, Shield Advanced, and VPC security group policies across multiple accounts. Another points out that D combines CloudFormation for consistent deployments, Firewall Manager for centralized policy management, and GuardDuty for monitoring, highlighting the operational efficiency. The comment thread confirms that Firewall Manager is the key service to remember for central policy governance.

Official Reference

Exam Strategy

When answering questions about central policy management across multiple AWS services, immediately look for AWS Firewall Manager as the central orchestration service. Remember that CloudFormation is for initial deployment, while Firewall Manager handles ongoing centralized governance; GuardDuty is for monitoring, not policy enforcement.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide