What Is the Most Efficient Way to Manage AWS Network Firewall, WAF, and Security Groups?
A company is planning to host external websites on AWS. The websites will include multiple tiers such as web servers, application logic services, and databases. The company wants to use AWS Network Firewall, AWS WAF, and VPC security groups for network security. The company must ensure that the Network Firewall firewalls are deployed appropriately within relevant VPCs. The company needs the ability to centrally manage policies that are deployed to Network Firewall and AWS WAF rules. The company also needs to allow application teams to manage their own security groups while ensuring that the security groups do not allow overly permissive access. What is the MOST operationally efficient solution that meets these requirements?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests your understanding that Firewall Manager is the central service for managing AWS WAF, Network Firewall, and security group policies across accounts, while CloudFormation handles the initial deployment.
This ANS-C01 question evaluates the best practice for centrally managing AWS Network Firewall, AWS WAF, and VPC security groups. The consensus answer is D, which combines CloudFormation for initial deployment, AWS Firewall Manager for centralized policy management, and GuardDuty for monitoring.
Choosing option A or B, which rely on CloudFormation or manual monitoring with GuardDuty to enforce overly permissive rules, instead of using AWS Firewall Manager for centralized and automated policy governance.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option D is correct because it leverages AWS Firewall Manager to centrally manage AWS WAFv2 web ACLs, Network Firewall policies, and VPC security groups. Firewall Manager is designed to apply and enforce security policies across multiple accounts and VPCs within an AWS Organization, making it the most operationally efficient choice. CloudFormation is used to deploy the initial objects and policies, while GuardDuty provides monitoring for overly permissive rules, complementing Firewall Manager's automated governance.Why the Other Options Are Wrong
Option A is incorrect because it uses CloudFormation to update policies and security groups, but CloudFormation does not provide centralized cross-account policy enforcement; GuardDuty only detects issues, it does not centrally manage policies. Option B is wrong because it relies on manual management via the console or CLI and uses a Lambda function to remove overly permissive rules, which is not as efficient or scalable as Firewall Manager. Option C is incomplete because it only deploys WAF IP sets and web ACLs with CloudFormation and uses Firewall Manager only for Network Firewall and security groups, missing the centralized management of WAFv2 web ACLs in the same manner as D.Community Comment Notes
Comments on this question overwhelmingly support D, with votes at 100%. One comment notes that Firewall Manager makes it easier to centrally configure and manage AWS WAF, Shield Advanced, and VPC security group policies across multiple accounts. Another points out that D combines CloudFormation for consistent deployments, Firewall Manager for centralized policy management, and GuardDuty for monitoring, highlighting the operational efficiency. The comment thread confirms that Firewall Manager is the key service to remember for central policy governance.Official Reference
Exam Strategy
When answering questions about central policy management across multiple AWS services, immediately look for AWS Firewall Manager as the central orchestration service. Remember that CloudFormation is for initial deployment, while Firewall Manager handles ongoing centralized governance; GuardDuty is for monitoring, not policy enforcement.
Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →