AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium

A security architect is comparing security groups and network ACLs (NACLs) within an Amazon VPC. Which statement correctly distinguishes the two?

  1. ABoth security groups and NACLs are stateless and operate only at the instance level
  2. BSecurity groups are stateful and operate at the instance level, while NACLs are stateless and operate at the subnet level
  3. CSecurity groups are stateless and operate at the subnet level, while NACLs are stateful and operate at the instance level
  4. DBoth security groups and NACLs are stateful and operate only at the subnet level
Show answer & explanation

Correct answer: B. Security groups are stateful and operate at the instance level, while NACLs are stateless and operate at the subnet level

Security groups act as a virtual firewall at the instance (ENI) level and are stateful, meaning return traffic is automatically allowed. NACLs act at the subnet level, are stateless, and require explicit rules for both inbound and outbound traffic.

Why the other options are wrong

  • A. Security groups are stateful, not stateless, so this is incorrect.
  • C. This reverses the correct stateful/stateless and level associations.
  • D. NACLs are stateless, not stateful, so this is incorrect.

Security Groups vs NACLs

Security groups are stateful firewalls applied at the instance level; NACLs are stateless firewalls applied at the subnet level.

  • Security groups: stateful, instance-level, allow rules only
  • NACLs: stateless, subnet-level, allow and deny rules
  • Return traffic auto-allowed by security groups, not by NACLs

Memory trick: Security groups guard the door (instance); NACLs guard the neighborhood (subnet).

More Security and Compliance questions