AWS Certified Cloud Practitioner (CLF-C02)Cloud Technology and ServicesHard
A security team needs to control traffic at the subnet level within a VPC, including the ability to explicitly DENY specific IP ranges, and wants the rules evaluated in numbered order as stateless filters. Which VPC feature should they configure?
- ASecurity Groups
- BVPC Peering
- CRoute Tables
- DNetwork ACLs
Show answer & explanationAnswer & explanation
Correct answer: D. Network ACLs
Network ACLs (NACLs) operate at the subnet level, are stateless, evaluate numbered rules in order, and support both ALLOW and explicit DENY rules, unlike Security Groups which only support ALLOW rules and are stateful.
Why the other options are wrong
- A. Security Groups are stateful and instance-level, and cannot explicitly deny traffic.
- B. VPC Peering connects two VPCs and has nothing to do with traffic filtering rules.
- C. Route Tables control routing of traffic, not allow/deny filtering.
Network ACLs
A stateless, subnet-level firewall in a VPC that evaluates numbered rules in order and supports both allow and explicit deny rules.
- Operate at the subnet level, not instance level
- Stateless — return traffic must be explicitly allowed
- Support explicit DENY rules, unlike Security Groups
Memory trick: NACL = 'Numbered gate that can say NO.'