CompTIA Cloud+ (CV0-004)DeploymentMedium
A development team is implementing a new microservices architecture in a public cloud. Each microservice needs to communicate with specific other microservices while restricting access from the internet and other unauthorized internal services. The team wants to define granular, stateful rules to control inbound and outbound traffic for each individual microservice instance. Which network security construct should they primarily use?
- AInternet Gateway
- BSecurity Group
- CNetwork Access Control List (NACL)
- DVirtual Private Cloud (VPC)
Show answer & explanationAnswer & explanation
Correct answer: B. Security Group
Security Groups provide stateful firewall rules that control inbound and outbound traffic for one or more instances. They are ideal for granular control at the instance level, allowing specific microservices to communicate while restricting others, and are stateful, meaning return traffic is automatically allowed.
Why the other options are wrong
- A. An Internet Gateway connects a VPC to the internet but doesn't provide granular traffic filtering for internal microservice communication.
- C. NACLs provide stateless firewall rules at the subnet level, which is less granular and not stateful, making them less suitable for instance-specific microservice communication.
- D. A VPC defines an isolated network space but doesn't provide granular instance-level traffic filtering.
Security Group
A virtual firewall that controls inbound and outbound traffic for one or more compute instances (e.g., EC2 instances, containers).
- Operates at the instance level.
- Is stateful, automatically allowing return traffic.
- Allows granular control over specific ports and protocols.
Memory trick: VPC for Isolation, NACL for Subnets, SG for Instances, IG for Internet.