AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceEasy
A company wants to deploy a managed network security service that provides stateful traffic inspection, intrusion prevention, and fine-grained filtering rules for traffic entering and leaving its Amazon VPCs. Which AWS service best fits this requirement?
- AAWS Network Firewall
- BAWS WAF
- CAWS Shield
- DSecurity groups
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Network Firewall
AWS Network Firewall is a managed, stateful network firewall service designed for VPC-level traffic filtering, including intrusion prevention and detection. WAF protects web applications at the HTTP layer, Shield defends against DDoS attacks, and security groups are instance-level stateful firewalls without intrusion prevention capabilities.
Why the other options are wrong
- B. WAF filters HTTP/HTTPS web traffic, not general VPC network traffic.
- C. Shield protects against DDoS attacks, not general traffic filtering.
- D. Security groups filter traffic per instance/ENI but lack IPS features.
AWS Network Firewall
A managed, stateful network firewall and intrusion prevention service for filtering traffic to and from Amazon VPCs.
- Operates at the VPC level, unlike security groups which are per-instance
- Supports domain filtering, stateful rules, and intrusion prevention signatures
- Integrates with AWS Firewall Manager for centralized policy management
Memory trick: Network Firewall guards the whole VPC gate, not just one door.