ANS-C01 · Question #233
A company is planning to host external websites on AWS. The websites will include multiple tiers such as web servers, application logic services, and databases. The company wants to use AWS Network…
The correct answer is D. Define Network Firewall firewalls, AWS WAFv2 web ACLS, Network Firewall policies, and VPC. Firewall Manager makes it easier to centrally configure and manage AWS WAF, AWS Shield Advanced, and VPC security group policies across multiple accounts and applications in an AWS Organization. It also manages AWS Network Firewall policies.
Question
A company is planning to host external websites on AWS. The websites will include multiple tiers such as web servers, application logic services, and databases. The company wants to use AWS Network Firewall, AWS WAF, and VPC security groups for network security. The company must ensure that the Network Firewall firewalls are deployed appropriately within relevant VPCs. The company needs the ability to centrally manage policies that are deployed to Network Firewall and AWS WAF rules. The company also needs to allow application teams to manage their own security groups while ensuring that the security groups do not allow overly permissive access. What is the MOST operationally efficient solution that meets these requirements?
Options
- ADefine Network Firewall firewalls, AWS WAFV2 web ACLs. Network Firewall policies, and VPC
- BDefine Network Firewall firewalls. AWS WAFV2 web ACLs, Network Firewall policies, and VPC
- CDeploy AWS WAFv2 IP sets and AWS WAFv2 web ACLs with AWS CloudFormation. Use AWS
- DDefine Network Firewall firewalls, AWS WAFv2 web ACLS, Network Firewall policies, and VPC
How the community answered
(60 responses)- A7% (4)
- B15% (9)
- C22% (13)
- D57% (34)
Explanation
Firewall Manager makes it easier to centrally configure and manage AWS WAF, AWS Shield Advanced, and VPC security group policies across multiple accounts and applications in an AWS Organization. It also manages AWS Network Firewall policies.
Community Discussion
No community discussion yet for this question.