AWS Certified Advanced Networking – Specialty (ANS-C01) — Question 199

A company is planning to host external websites on AWS. The websites will include multiple tiers such as web servers, application logic services, and databases. The company wants to use AWS Network Firewall, AWS WAF, and VPC security groups for network security.

The company must ensure that the Network Firewall firewalls are deployed appropriately within relevant VPCs. The company needs the ability to centrally manage policies that are deployed to Network Firewall and AWS WAF rules. The company also needs to allow application teams to manage their own security groups while ensuring that the security groups do not allow overly permissive access.

What is the MOST operationally efficient solution that meets these requirements?

Answer options

Correct answer: D

Explanation

Option D is the most operationally efficient solution because it combines code-based infrastructure management with AWS Firewall Manager for centralized governance of security policies, while also using Amazon GuardDuty for monitoring. The other options either rely on manual management through the AWS Management Console or do not utilize AWS Firewall Manager, which would reduce efficiency and scalability in managing security configurations.