AWS Certified Security – Specialty — Question 177

A company uses multiple AWS accounts managed with AWS Organizations. Security engineers have created a standard set of security groups for all these. accounts. The security policy requires that these security groups be used for all applications and delegates modification authority to the security team only.
A recent security audit found that the security groups are inconsistently implemented across accounts and that unauthorized changes have been made to the security groups. A security engineer needs to recommend a solution to improve consistency and to prevent unauthorized changes in the individual accounts in the future.
Which solution should the security engineer recommend?

Answer options

Correct answer: C

Explanation

The correct answer is C because AWS Firewall Manager can create security group policies that help maintain consistency across accounts and automatically revert unauthorized changes. Option A is incorrect as read-only access does not prevent unauthorized changes. Option B, while it helps in creating security groups, does not ensure ongoing compliance or prevent modifications. Option D focuses on sharing security groups but does not address the need for automatic remediation of changes.