AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceEasy

A company wants to deploy a managed network security service that provides stateful traffic inspection, intrusion prevention, and fine-grained filtering rules for traffic entering and leaving its Amazon VPCs. Which AWS service best fits this requirement?

  1. AAWS Network Firewall
  2. BAWS WAF
  3. CAWS Shield
  4. DSecurity groups
Show answer & explanation

Correct answer: A. AWS Network Firewall

AWS Network Firewall is a managed, stateful network firewall service designed for VPC-level traffic filtering, including intrusion prevention and detection. WAF protects web applications at the HTTP layer, Shield defends against DDoS attacks, and security groups are instance-level stateful firewalls without intrusion prevention capabilities.

Why the other options are wrong

  • B. WAF filters HTTP/HTTPS web traffic, not general VPC network traffic.
  • C. Shield protects against DDoS attacks, not general traffic filtering.
  • D. Security groups filter traffic per instance/ENI but lack IPS features.

AWS Network Firewall

A managed, stateful network firewall and intrusion prevention service for filtering traffic to and from Amazon VPCs.

  • Operates at the VPC level, unlike security groups which are per-instance
  • Supports domain filtering, stateful rules, and intrusion prevention signatures
  • Integrates with AWS Firewall Manager for centralized policy management

Memory trick: Network Firewall guards the whole VPC gate, not just one door.

More Security and Compliance questions