CompTIA Cloud+ (CV0-004)TroubleshootingMedium

A cloud security engineer needs to implement strict network segmentation for a highly sensitive application. The application consists of a web tier, an application tier, and a database tier, each deployed in its own subnet within a VPC. Traffic must only flow in specific directions (e.g., web to app, app to DB). Which network security construct is MOST effective for enforcing this granular, stateful traffic flow between subnets?

  1. AFirewall appliances deployed as network virtual appliances (NVAs).
  2. BSecurity Groups.
  3. CRoute Tables.
  4. DVPC Network Access Control Lists (NACLs).
Show answer & explanation

Correct answer: B. Security Groups.

Security Groups are stateful firewalls that operate at the instance level, allowing for granular control over inbound and outbound traffic for individual instances or groups of instances. This makes them ideal for enforcing specific, directional traffic flows between application tiers.

Why the other options are wrong

  • A. While NVAs can provide advanced firewall capabilities, Security Groups are typically the native and more integrated cloud solution for granular, stateful instance-level traffic control within a VPC, often with better performance and simpler management for common scenarios.
  • C. Route tables define how network traffic is directed between subnets, to the internet, or other destinations, but they do not enforce security policies or filter traffic based on ports or protocols.
  • D. NACLs are stateless and operate at the subnet level. While they can control traffic, they are less granular and more cumbersome for stateful, directional rules between specific instances or tiers.

Cloud Security Groups

A virtual firewall that controls inbound and outbound traffic for one or more virtual instances, operating at the instance level and maintaining connection state.

  • Stateful: automatically allows return traffic for established connections.
  • Instance-level control: rules apply to instances, not subnets.
  • Granular: allows specific port, protocol, and source/destination IP rules.

Memory trick: Security groups are like bodyguards for each server, watching who comes and goes.

More Troubleshooting questions