Ultimate access to all questions.
A company's AWS infrastructure spans over 50 accounts and five AWS Regions. To manage its security posture with simplified administration and maintenance across all accounts, the company plans to use AWS Firewall Manager for firewall rule management. The company has already created an organization with all features enabled in AWS Organizations.
Which three steps should the company take next to fulfill these requirements?
Explanation:
To meet the company's requirements for managing its security posture across multiple AWS accounts and regions using AWS Firewall Manager, the following steps are necessary: First, the company needs to set an account as the Firewall Manager administrator account (C). This account will have the permissions to manage firewall rules across the organization. Second, all the accounts should be configured to join the organization (B). This is essential for the Firewall Manager administrator account to manage the firewall rules across all accounts. Third, AWS Config should be set up for all the accounts and all the Regions where the company has resources (E). AWS Config is necessary for tracking the configuration changes and ensuring compliance with the desired security posture across the organization. Option A is incorrect because only configuring the Firewall Manager administrator account to join the organization is not sufficient; all accounts need to be part of the organization. Option D is incorrect because there is no concept of a 'Firewall Manager child account' in this context. Option F is incorrect because setting up AWS Config for only the organization's management account does not provide the necessary coverage across all accounts and regions.