AWS Network Firewall with Auto Scaling and Resource Groups

A company uses AWS Network Firewall to protect outgoing traffic for multiple VPCs that are in the same AWS account. Each VPC contains Amazon EC2 instances that host the company's applications. Each EC2 instance is tagged with the name of the application it hosts. The EC2 instances are in Auto Scaling groups. A Network Firewall stateful rule group must remain up-to-date, even when an Auto Scaling group launches and terminates EC2 instances. Which solution will meet this requirement with the LEAST implementation and administrative effort?

  1. Create a network ACL for each application. Reference the network ACL in the stateful rule group.
  2. Create a prefix list for each application. Reference the prefix list in the stateful rule group.
  3. Create an AWS Lambda function that queries the EC2 instance tags for each application name and then updates the stateful rule group with the IP address of each instance.
  4. Create a resource group for each application name. Reference the Amazon Resource Name (ARN) for the resource groups in the stateful rule group. Source Reference Answer

Community Votes

D
83%
B
17%

83% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests knowledge of AWS Network Firewall's native support for Resource Group ARNs to automatically reflect changes in instance tags without manual intervention or custom code.

This question tests the integration of AWS Network Firewall with dynamic infrastructure using Resource Groups. The community consensus is that Resource Groups provide a zero-maintenance, tag-based solution for updating firewall rules as instances scale.

Candidates often choose Prefix Lists (Option B), assuming they are the standard dynamic IP management tool. However, Prefix Lists require manual updates or complex Lambda automation to track specific instance IPs, whereas Resource Groups handle this natively via tags.

Community Discussion (3 comments)

ashk123456 👍 1 Selected: B
Prefix lists in AWS are dynamic collections of IP address ranges (CIDR blocks) that can be referenced within Network Firewall rules. When you maintain and update a prefix list to include the subnets where your Auto Scaling groups operate, the Network Firewall rules automatically apply to any new instances launched in those subnets. ❌ D. Resource groups cannot be referenced in firewall rule groups. ----AWS Network Firewall does not support referencing resource groups in rule groups.
woorkim 👍 2 Selected: D
because: Resource groups automatically update membership based on tags No ongoing maintenance required once set up Handles Auto Scaling events automatically Minimal implementation effort (just create groups and reference ARNs) No custom code or manual updates needed Works with Network Firewall's native capabilities
c1193d4 👍 3 Selected: D
D: because a tag-based resource group can be created : see https://docs.aws.amazon.com/network-firewall/latest/developerguide/resource-groups.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option D is correct because AWS Network Firewall supports referencing Resource Groups directly in stateful rule groups. When you create a resource group based on EC2 instance tags, it automatically includes new instances launched by Auto Scaling and excludes terminated ones. This eliminates the need for any custom scripting or manual IP management.

Why the Other Options Are Wrong

Option A is incorrect because Network ACLs operate at the subnet level and do not integrate with Network Firewall stateful rules. Option B is incorrect because while Prefix Lists are dynamic for CIDR blocks, they do not automatically update based on EC2 instance tags or individual IP addresses without external configuration. Option C involves significant administrative effort to write, deploy, and maintain a Lambda function, violating the 'least effort' requirement.

Community Comment Notes

Comment [1] and [2] correctly cite the official documentation confirming that Resource Groups can be used with Network Firewall. Comment [3] incorrectly claims Resource Groups cannot be referenced, which contradicts current AWS capabilities; this highlights a common misconception among candidates relying on outdated information.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide