CompTIA Cloud+ (CV0-004)Cloud ArchitectureHard
A cloud security architect is designing the network security for a multi-tier application within a Virtual Private Cloud (VPC). The architect needs to implement stateless filtering at the subnet level to control inbound and outbound traffic, allowing or denying traffic based on IP addresses and ports, before it reaches the instances. Which security component should be configured?
- ANetwork Access Control List (NACL)
- BSecurity Group
- CHost-based Firewall
- DWeb Application Firewall (WAF)
Show answer & explanationAnswer & explanation
Correct answer: A. Network Access Control List (NACL)
A Network Access Control List (NACL) provides stateless packet filtering at the subnet level, allowing or denying traffic based on rules, and processes rules in order.
Why the other options are wrong
- B. A Security Group provides stateful filtering at the instance level, allowing return traffic automatically once a connection is established.
- C. A Host-based Firewall operates on individual instances (e.g., iptables, Windows Firewall) and is not a VPC-level component for subnet filtering.
- D. A Web Application Firewall (WAF) protects web applications from common web exploits, operating at the application layer, not at the subnet level for general traffic filtering.
Network Access Control List (NACL)
A Network Access Control List (NACL) is an optional layer of security for your VPC that acts as a stateless firewall for controlling traffic in and out of one or more subnets. Rules are processed in order, and it applies to all instances within the associated subnets.
- Operates at the subnet level
- Stateless filtering (inbound and outbound rules are separate)
- Rules are processed in order (lowest rule number evaluated first)
- Default NACLs allow all inbound/outbound traffic
- Custom NACLs deny all traffic by default implicitly
Memory trick: NACL is the 'bouncer' at the subnet entrance, checking everyone, both ways, against a strict rule list.