Correct Answer: B
AWS Firewall Manager makes it possible to manage VPC security groups, AWS Shield Advanced and WAF rules on one platform even across multiple AWS accounts.
https://docs.aws.amazon.com/waf/latest/developerguide/fms-chapter.html
Option A is INCORRECT because AWS Identity & Access Management (IAM) does not allow for the management of VPC security groups or WAF rules.
Option C is INCORRECT because Amazon Cloud Directory is a repository for developer objects. The service does not have the functionality to centrally manage all the VPC security groups or WAF rules in the AWS environment.
Option D is INCORRECT because AWS Security Hub is a full-view, single-look, comprehensive depiction of the security state of the customer’s AWS environment. The service collates security data across AWS accounts and facilitates the analysis of data security patterns. It identifies the highest priority security areas in the customer’s AWS environment.