
Answer-first summary for fast verification
Answer: Create a firewall policy or rule group in the management account, Use AWS Resource Access Manager (AWS RAM) to share the firewall policy or rule group., Enable sharing within Organizations.
To minimize the number of firewall policies and rule groups necessary for web filtering across 50 AWS accounts within an AWS Organization, the network engineer should leverage AWS Resource Access Manager (AWS RAM) and AWS Organizations features. This approach allows for the central management and sharing of resources across accounts, reducing redundancy and simplifying management. The correct steps are: C. Create a firewall policy or rule group in the management account, D. Use AWS Resource Access Manager (AWS RAM) to share the firewall policy or rule group, and E. Enable sharing within Organizations. Creating the firewall policy or rule group in the management account (C) centralizes the management of these resources. Using AWS RAM (D) facilitates the sharing of these resources across accounts within the organization, ensuring consistency and reducing the need to create multiple policies or rule groups. Enabling sharing within Organizations (E) is a prerequisite for using AWS RAM to share resources across accounts in the organization. This combination ensures that the web filtering requirements are met efficiently and with minimal administrative overhead.
Author: LeetQuiz Editorial Team
Ultimate access to all questions.
A company with VPCs across 50 AWS accounts, utilizing AWS Organizations, aims to implement consistent web filtering across all VPCs using AWS Network Firewall. The network engineer seeks to minimize the number of firewall policies and rule groups required.
Which three-step combination will fulfill these requirements? (Choose three.)
A
Create a firewall policy or rule group in each account.
B
Use SCPs to share the firewall policy or rule group.
C
Create a firewall policy or rule group in the management account
D
Use AWS Resource Access Manager (AWS RAM) to share the firewall policy or rule group.
E
Enable sharing within Organizations.
No comments yet.