exam questions

Exam AWS DevOps Engineer Professional All Questions

View all questions & answers for the AWS DevOps Engineer Professional exam

Exam AWS DevOps Engineer Professional topic 1 question 203 discussion

Exam question from Amazon's AWS DevOps Engineer Professional
Question #: 203
Topic #: 1
[All AWS DevOps Engineer Professional Questions]

A company uses Application Load Balancers (ALBs) as part of its application architecture. The company has ALBs in AWS accounts that are part of an organization in AWS Organizations. The company has configured AWS Config in all AWS accounts in the organization.

The company needs to apply an AWS WAF web ACL with a common set of rules to all ALBs, including any ALBs that are created in the future. Administrators of each AWS account must be able to define their own AWS WAF rules that are in addition to the common rules that the company’s security team provides for all the accounts.

Which solution will meet these requirements?

  • A. Configure AWS Firewall Manager for the organization. In the Firewall Manager administrator account, create an AWS WAF policy. Turn on automatic remediation and define the web ACL. Configure the policy scope to apply to all ALBs in the organization.
  • B. Use AWS Resource Access Manager (AWS RAM) from the organization's management account to enable resource sharing in the organization. Create the web ACL. Configure a resource share of the web ACL for the organization. Associate the shared web ACL with all the ALBs in the organization.
  • C. Set up the ALB_WAF_ENABLED AWS Config managed rule with automatic remediation. Configure the rule to create the web ACL and to attach the web ACL to all ALBs in an AWS account. Create an AWS Config conformance pack that contains the rule. Deploy the conformance pack to all AWS accounts in the organization.
  • D. Configure AWS Firewall Manager for the organization. In the Firewall Manager administrator account, create an AWS WAF policy that defines the web ACL. Set up the ALB_WAF_ENABLED AWS Config managed rule with automatic remediation. Configure the rule to attach the web ACL to all ALBs in an AWS account. Deploy the rule to all AWS accounts in the organization.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
easytoo
2 years ago
It's B. Good old RAM to the rescue.
upvoted 1 times
...
merki
2 years ago
ChatGPT: Option D is the correct solution. This solution involves using AWS Firewall Manager to centrally manage the AWS WAF policy and web ACL for all ALBs in the organization. In the Firewall Manager administrator account, a web ACL is created and defined in an AWS WAF policy. The policy is then deployed to all AWS accounts in the organization. Next, the ALB_WAF_ENABLED AWS Config managed rule is set up in each AWS account with automatic remediation. This rule will attach the web ACL defined in the AWS WAF policy to all ALBs in the account. This approach allows each AWS account to have its own AWS WAF rules in addition to the common set of rules provided by the company’s security team. The central management of the AWS WAF policy and web ACL ensures consistency across all ALBs in the organization, including any ALBs that are created in the future.
upvoted 2 times
...
CloudFloater
2 years, 2 months ago
Selected Answer: A
revising to A, since WAF is not shareable per saeidp link below.
upvoted 2 times
...
SS2023
2 years, 2 months ago
Selected Answer: A
I like A based on the link saeidp posted
upvoted 1 times
...
saeidp
2 years, 2 months ago
Selected Answer: A
A for me AWS config is only used for detecting the new resources https://aws.amazon.com/blogs/security/using-aws-firewall-manager-and-waf-to-protect-your-web-applications-with-master-rules-and-application-specific-rules/
upvoted 3 times
saeidp
2 years, 2 months ago
By the way WAF acl are not part of shareables from RAM https://docs.aws.amazon.com/ram/latest/userguide/shareable.html
upvoted 3 times
...
...
CloudFloater
2 years, 2 months ago
Selected Answer: B
Option A is incorrect because AWS Firewall Manager is not necessary to achieve the goal. Option B is the better solution because it uses AWS RAM to share the web ACL across all accounts. Option C is incorrect because it applies only to AWS Config and does not provide a solution for deploying the web ACL. Option D is incorrect because it also involves AWS Firewall Manager, which is not necessary to achieve the goal.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago