CompTIA Security+ (SY0-701)Security ArchitectureHard
A cloud architect configures a virtual private cloud (VPC) so that a compromised web application server in one subnet cannot initiate connections to a database subnet unless explicitly permitted by rules evaluated on every packet crossing the subnet boundary, including return traffic. Which cloud networking control is being described?
- ASecurity group
- BNAT gateway
- CRoute table
- DNetwork access control list (NACL)
Show answer & explanationAnswer & explanation
Correct answer: D. Network access control list (NACL)
A network ACL is a stateless, subnet-level control that evaluates both inbound and outbound rules for every packet, including return traffic, unlike security groups which are stateful and automatically allow return traffic once an initial connection is permitted.
Why the other options are wrong
- A. Security groups are stateful and instance-level; they automatically allow return traffic without separate rules.
- B. A NAT gateway allows outbound internet access for private subnets, unrelated to inter-subnet filtering.
- C. A route table determines the path traffic takes, not whether it's permitted.
Network ACL (NACL)
A stateless, subnet-level firewall in cloud networking that evaluates inbound and outbound rules for every packet, requiring explicit rules for both request and return traffic.
- Stateless: return traffic must be explicitly allowed
- Operates at the subnet level, not per-instance
- Contrasts with stateful security groups
Memory trick: NACL checks every packet, coming and going.