nerdexam
Amazon

ANS-C01 · Question #223

A company's AWS infrastructure is spread across more than 50 accounts and across five AWS Regions. The company needs to manage its security posture with simplified administration and maintenance for…

The correct answer is B. Configure all the accounts to join the organization. C. Set an account as the Firewall Manager administrator account. E. Set up AWS Config for all the accounts and all the Regions where the company has resources. The company wants to implement AWS Firewall Manager for centralized security posture management across many accounts and regions within an AWS Organization.

Submitted by kev92· Mar 6, 2026Network Security, Compliance, and Governance

Question

A company's AWS infrastructure is spread across more than 50 accounts and across five AWS Regions. The company needs to manage its security posture with simplified administration and maintenance for all the AWS accounts. The company wants to use AWS Firewall Manager to manage the firewall rules and requirements. The company creates an organization with all features enabled in AWS Organizations. Which combination of steps should the company take next to meet the requirements? (Choose three.)

Options

  • AConfigure only the Firewall Manager administrator account to join the organization.
  • BConfigure all the accounts to join the organization.
  • CSet an account as the Firewall Manager administrator account.
  • DSet an account as the Firewall Manager child account.
  • ESet up AWS Config for all the accounts and all the Regions where the company has resources.
  • FSet up AWS Config for only the organization's management account.

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    82% (23)
  • D
    11% (3)
  • F
    4% (1)

Why each option

The company wants to implement AWS Firewall Manager for centralized security posture management across many accounts and regions within an AWS Organization.

AConfigure only the Firewall Manager administrator account to join the organization.

Configuring *only* the Firewall Manager administrator account to join the organization is incorrect; all accounts where resources are to be managed by Firewall Manager must be part of the organization.

BConfigure all the accounts to join the organization.Correct

All accounts must join the organization so that AWS Firewall Manager can discover and manage resources (like VPCs and their firewalls) across these accounts. Firewall Manager operates at the organization level.

CSet an account as the Firewall Manager administrator account.Correct

An account must be designated as the Firewall Manager administrator account. This account has the necessary permissions to configure and deploy Firewall Manager policies across the entire organization.

DSet an account as the Firewall Manager child account.

There is no concept of a "Firewall Manager child account" as a distinct configuration step; accounts are simply members of the organization.

ESet up AWS Config for all the accounts and all the Regions where the company has resources.Correct

AWS Config must be set up for all accounts and all regions where the company has resources. Firewall Manager relies on AWS Config to evaluate compliance and ensure that security policies are consistently applied across the organization's resources.

FSet up AWS Config for only the organization's management account.

Setting up AWS Config *only* for the organization's management account is insufficient. Firewall Manager needs AWS Config to be enabled in all member accounts and regions to monitor resource compliance and deploy policies effectively across the distributed infrastructure.

Concept tested: AWS Firewall Manager prerequisites and setup

Source: https://docs.aws.amazon.com/waf/latest/developerguide/fms-getting-started.html

Community Discussion

No community discussion yet for this question.

Full ANS-C01 Practice