AWS Certified Solutions Architect – Professional (SAP-C02) — Question 107

A company wants to deploy an AWS WAF solution to manage AWS WAF rules across multiple AWS accounts. The accounts are managed under different OUs in AWS Organizations.

Administrators must be able to add or remove accounts or OUs from managed AWS WAF rule sets as needed. Administrators also must have the ability to automatically update and remediate noncompliant AWS WAF rules in all accounts.

Which solution meets these requirements with the LEAST amount of operational overhead?

Answer options

Correct answer: A

Explanation

Option A is correct because AWS Firewall Manager provides a centralized way to manage WAF rules across multiple accounts with minimal operational overhead. The other options involve more complex setups, such as deploying AWS Config rules or using AWS Lambda for cross-account management, which increases the operational burden.