AWS Firewall Manager and Config Prerequisites
A company's AWS infrastructure is spread across more than 50 accounts and across five AWS Regions. The company needs to manage its security posture with simplified administration and maintenance for all the AWS accounts. The company wants to use AWS Firewall Manager to manage the firewall rules and requirements. The company creates an organization with all features enabled in AWS Organizations. Which combination of steps should the company take next to meet the requirements? (Choose three.)
Community Votes
100% of anonymous learners picked answer BCE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the specific architectural prerequisites for AWS Firewall Manager; the trap is thinking only the admin account needs configuration, whereas AWS Config must be enabled in all accounts/regions to detect non-compliant resources.
To centrally manage security posture across multiple AWS accounts using Firewall Manager, you must enable full AWS Organizations, designate a Firewall Manager administrator, and deploy AWS Config. Community consensus confirms that these three steps are mandatory prerequisites for centralized policy management.
Candidates often select options limiting scope to just the admin account (like A) or miss AWS Config entirely. They fail to realize that Firewall Manager relies on AWS Config to assess compliance across the entire organization, requiring it to be active everywhere.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
BCE is the correct combination because AWS Firewall Manager requires an organizational structure to function at scale. Option B ensures all accounts are part of the AWS Organization, which is the foundation for centralized management. Option C designates the central control plane (the Admin account). Option E enables AWS Config, which is a strict prerequisite for Firewall Manager to evaluate resource compliance and enforce policies.Why the Other Options Are Wrong
Option A is incorrect because restricting the organization to only the admin account prevents the other 50+ accounts from being managed. Option D is not a standard configuration step; accounts are simply members of the organization, not explicitly set as 'child accounts' for Firewall Manager purposes. Missing AWS Config (Option E) would leave the company unable to monitor security posture effectively.Community Comment Notes
Comment [2] correctly highlights that AWS Config enables centralized monitoring across regions. Comment [3] explicitly lists the prerequisites: Full AWS Organizations, AWS Config, and RAM. These comments reinforce that skipping any of these components breaks the centralized security model.Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →