CompTIA Cloud Essentials+ (CLO-002)Management and Technical OperationsHard
A cloud security engineer is tasked with implementing a policy that restricts network access between different development environments (Dev, Test, Prod) within the same Virtual Private Cloud (VPC). Specifically, resources in the Dev environment should not be able to initiate connections to resources in the Production environment, but Test can connect to Dev. Which networking construct is most suitable for enforcing such granular network segmentation within a VPC?
- ANetwork Access Control List (NACL)
- BVPC peering
- CVPN connection
- DInternet Gateway
Show answer & explanationAnswer & explanation
Correct answer: A. Network Access Control List (NACL)
NACLs are stateless firewalls that operate at the subnet level within a VPC, allowing for granular control over inbound and outbound traffic. They are ideal for enforcing strict segmentation rules between subnets, such as preventing Dev from connecting to Prod while allowing Test to Dev.
Why the other options are wrong
- B. VPC peering connects two VPCs, which is not necessary for segmentation *within* the same VPC.
- C. A VPN connection creates a secure tunnel between networks, typically on-premises and cloud, or between VPCs, not for granular subnet-level segmentation within a single VPC.
- D. An Internet Gateway allows communication between a VPC and the internet, not for internal segmentation.
Network Access Control List (NACL)
A stateless firewall that controls traffic in and out of one or more subnets within a virtual private cloud (VPC).
- Operates at the subnet level.
- Rules are evaluated in order, from lowest to highest number.
- Stateless: separate rules for inbound and outbound traffic.
- Can be used to block specific IPs or ports.
Memory trick: NACLs are the Neighborhood's Access Control Lists.