CompTIA Cloud+ (CV0-004)Cloud ArchitectureMedium

A cloud administrator is configuring a Virtual Private Cloud (VPC) and needs to define specific rules for inbound and outbound traffic at the subnet level. These rules should be stateless and apply to all instances within the subnet. Which security component should the administrator use?

  1. ANetwork Access Control List (NACL)
  2. BRoute Table
  3. CSecurity Group
  4. DVPC Flow Logs
Show answer & explanation

Correct answer: A. Network Access Control List (NACL)

A Network Access Control List (NACL) is a stateless firewall that controls traffic at the subnet level, applying rules to all instances within that subnet. Its stateless nature means that both inbound and outbound rules must be explicitly defined.

Why the other options are wrong

  • B. Route Tables define how network traffic is directed, not firewall rules.
  • C. Security Groups are stateful firewalls that operate at the instance level.
  • D. VPC Flow Logs capture information about IP traffic, they are for monitoring, not controlling traffic.

Network Access Control List (NACL)

A stateless firewall that operates at the subnet level in a Virtual Private Cloud (VPC), allowing or denying traffic based on rules.

  • Stateless: must define rules for both inbound and outbound traffic.
  • Applies to all instances within a subnet.
  • Acts as a second layer of defense after Security Groups.

Memory trick: NACLs are 'Nasty' 'Access' 'Control' 'Lists' that 'Stop' traffic at the 'Subnet' border, 'both ways'.

More Cloud Architecture questions