CompTIA Cloud+ (CV0-004)DeploymentMedium

A cloud engineer is designing a network for a multi-tier application in a public cloud. The application requires strict isolation between the web, application, and database tiers. Each tier must reside in its own subnet, and communication between tiers must be explicitly controlled. Which network component is primarily used to achieve this logical segmentation and control traffic flow between subnets?

  1. ANetwork Access Control List (NACL)
  2. BInternet Gateway
  3. CRoute Table
  4. DVirtual Private Gateway
Show answer & explanation

Correct answer: A. Network Access Control List (NACL)

Network Access Control Lists (NACLs) operate at the subnet level and provide stateless packet filtering, allowing or denying traffic into and out of entire subnets. This makes them ideal for enforcing strict isolation and controlling traffic flow between different application tiers residing in separate subnets.

Why the other options are wrong

  • B. An Internet Gateway allows communication between a VPC and the internet, not for internal subnet control.
  • C. Route Tables define how network traffic is directed, but don't filter or control access at the packet level like NACLs.
  • D. A Virtual Private Gateway connects a VPC to an on-premises network, not for inter-subnet control.

Network Access Control List (NACL)

A stateless firewall that controls traffic in and out of subnets in a virtual private cloud.

  • Operates at the subnet level.
  • Stateless: separate rules for inbound and outbound traffic.
  • Provides an additional layer of security beyond security groups.

Memory trick: NACLs are like subnet gatekeepers.

More Deployment questions