nerdexam
Amazon

SAP-C02 · Question #468

A company is using an organization in AWS Organizations to manage hundreds of AWS accounts. A solutions architect is working on a solution to provide baseline protection for the Open Web Application S

The correct answer is A. Enable AWS Config in all accounts C. Enable all features for the organization D. Use AWS Firewall Manager to deploy AWS WAF rules in all accounts for all CloudFront. A solutions architect must centrally deploy AWS WAF baseline protection for OWASP Top 10 vulnerabilities across all existing and new CloudFront distributions within an AWS organization with hundreds of accounts.

Submitted by olafpl· Mar 6, 2026Design Solutions for Organizational Complexity

Question

A company is using an organization in AWS Organizations to manage hundreds of AWS accounts. A solutions architect is working on a solution to provide baseline protection for the Open Web Application Security Project (OWASP) top 10 web application vulnerabilities. The solutions architect is using AWS WAF for all existing and new Amazon CloudFront distributions that are deployed within the organization. Which combination of steps should the solutions architect take to provide the baseline protection? (Choose three.)

Options

  • AEnable AWS Config in all accounts
  • BEnable Amazon GuardDuty in all accounts
  • CEnable all features for the organization
  • DUse AWS Firewall Manager to deploy AWS WAF rules in all accounts for all CloudFront
  • EUse AWS Shield Advanced to deploy AWS WAF rules in all accounts for all CloudFront
  • FUse AWS Security Hub to deploy AWS WAF rules in all accounts for all CloudFront distributions

How the community answered

(37 responses)
  • A
    68% (25)
  • B
    5% (2)
  • E
    8% (3)
  • F
    19% (7)

Why each option

A solutions architect must centrally deploy AWS WAF baseline protection for OWASP Top 10 vulnerabilities across all existing and new CloudFront distributions within an AWS organization with hundreds of accounts.

AEnable AWS Config in all accountsCorrect

Enabling AWS Config in all accounts allows for continuous monitoring and assessment of compliance with security policies, including the AWS WAF rules deployed by Firewall Manager, ensuring the baseline protection is consistently applied and maintained.

BEnable Amazon GuardDuty in all accounts

Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, but it does not deploy or manage AWS WAF rules.

CEnable all features for the organizationCorrect

Enabling "all features" for the organization is a prerequisite for using AWS Firewall Manager to centrally manage and deploy AWS WAF rules across all member accounts within an AWS Organization.

DUse AWS Firewall Manager to deploy AWS WAF rules in all accounts for all CloudFrontCorrect

AWS Firewall Manager is the dedicated service for centrally configuring and deploying AWS WAF rules across multiple AWS accounts and resources (like CloudFront distributions) within an AWS Organization, effectively providing the desired baseline protection for OWASP Top 10 vulnerabilities.

EUse AWS Shield Advanced to deploy AWS WAF rules in all accounts for all CloudFront

AWS Shield Advanced provides enhanced DDoS protection and includes AWS WAF, but AWS Firewall Manager is the service specifically designed for centralized deployment and management of WAF rules across an organization.

FUse AWS Security Hub to deploy AWS WAF rules in all accounts for all CloudFront distributions

AWS Security Hub aggregates security findings from various AWS services and helps with security posture management, but it does not deploy or manage AWS WAF rules.

Concept tested: Centralized security policy management with AWS Firewall Manager

Source: https://docs.aws.amazon.com/waf/latest/developerguide/fms-getting-started.html

Community Discussion

No community discussion yet for this question.

Full SAP-C02 Practice