AWS Network Firewall with Auto Scaling and Resource Groups
A company uses AWS Network Firewall to protect outgoing traffic for multiple VPCs that are in the same AWS account. Each VPC contains Amazon EC2 instances that host the company's applications. Each EC2 instance is tagged with the name of the application it hosts. The EC2 instances are in Auto Scaling groups. A Network Firewall stateful rule group must remain up-to-date, even when an Auto Scaling group launches and terminates EC2 instances. Which solution will meet this requirement with the LEAST implementation and administrative effort?
Community Votes
83% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests knowledge of AWS Network Firewall's native support for Resource Group ARNs to automatically reflect changes in instance tags without manual intervention or custom code.
This question tests the integration of AWS Network Firewall with dynamic infrastructure using Resource Groups. The community consensus is that Resource Groups provide a zero-maintenance, tag-based solution for updating firewall rules as instances scale.
Candidates often choose Prefix Lists (Option B), assuming they are the standard dynamic IP management tool. However, Prefix Lists require manual updates or complex Lambda automation to track specific instance IPs, whereas Resource Groups handle this natively via tags.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option D is correct because AWS Network Firewall supports referencing Resource Groups directly in stateful rule groups. When you create a resource group based on EC2 instance tags, it automatically includes new instances launched by Auto Scaling and excludes terminated ones. This eliminates the need for any custom scripting or manual IP management.Why the Other Options Are Wrong
Option A is incorrect because Network ACLs operate at the subnet level and do not integrate with Network Firewall stateful rules. Option B is incorrect because while Prefix Lists are dynamic for CIDR blocks, they do not automatically update based on EC2 instance tags or individual IP addresses without external configuration. Option C involves significant administrative effort to write, deploy, and maintain a Lambda function, violating the 'least effort' requirement.Community Comment Notes
Comment [1] and [2] correctly cite the official documentation confirming that Resource Groups can be used with Network Firewall. Comment [3] incorrectly claims Resource Groups cannot be referenced, which contradicts current AWS capabilities; this highlights a common misconception among candidates relying on outdated information.Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →