AWS Firewall Manager and Config Prerequisites

A company's AWS infrastructure is spread across more than 50 accounts and across five AWS Regions. The company needs to manage its security posture with simplified administration and maintenance for all the AWS accounts. The company wants to use AWS Firewall Manager to manage the firewall rules and requirements. The company creates an organization with all features enabled in AWS Organizations. Which combination of steps should the company take next to meet the requirements? (Choose three.)

  1. Configure only the Firewall Manager administrator account to join the organization.
  2. Configure all the accounts to join the organization. Source Reference Answer
  3. Set an account as the Firewall Manager administrator account. Source Reference Answer
  4. Set an account as the Firewall Manager child account.
  5. Set up AWS Config for all the accounts and all the Regions where the company has resources. Source Reference Answer

Community Votes

BCE
100%

100% of anonymous learners picked answer BCE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the specific architectural prerequisites for AWS Firewall Manager; the trap is thinking only the admin account needs configuration, whereas AWS Config must be enabled in all accounts/regions to detect non-compliant resources.

To centrally manage security posture across multiple AWS accounts using Firewall Manager, you must enable full AWS Organizations, designate a Firewall Manager administrator, and deploy AWS Config. Community consensus confirms that these three steps are mandatory prerequisites for centralized policy management.

Candidates often select options limiting scope to just the admin account (like A) or miss AWS Config entirely. They fail to realize that Firewall Manager relies on AWS Config to assess compliance across the entire organization, requiring it to be active everywhere.

Community Discussion (4 comments)

AzureDP900 👍 2 Selected: BCE
Option B ensures that all 50+ AWS accounts are under the same management, making it easier to manage security posture. Option C sets up an administrator account within one of these accounts, which can manage all Firewall Manager configurations across the organization. Option E enables centralized monitoring and compliance for resources across all Regions, allowing the company to maintain consistency in their AWS security posture.
woorkim 👍 1 Selected: BCE
Pre-requisites for Firewall Manager • Enable AWS Organization (full features) • Enable AWS Config • Enable AWS Resource Access Manager (RAM)
cas_tori 👍 1 Selected: BCE
this is BCE
rdiaz 👍 4 Selected: BCE
All accounts, firewall parent and aws config in all accounts.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

BCE is the correct combination because AWS Firewall Manager requires an organizational structure to function at scale. Option B ensures all accounts are part of the AWS Organization, which is the foundation for centralized management. Option C designates the central control plane (the Admin account). Option E enables AWS Config, which is a strict prerequisite for Firewall Manager to evaluate resource compliance and enforce policies.

Why the Other Options Are Wrong

Option A is incorrect because restricting the organization to only the admin account prevents the other 50+ accounts from being managed. Option D is not a standard configuration step; accounts are simply members of the organization, not explicitly set as 'child accounts' for Firewall Manager purposes. Missing AWS Config (Option E) would leave the company unable to monitor security posture effectively.

Community Comment Notes

Comment [2] correctly highlights that AWS Config enables centralized monitoring across regions. Comment [3] explicitly lists the prerequisites: Full AWS Organizations, AWS Config, and RAM. These comments reinforce that skipping any of these components breaks the centralized security model.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide