CompTIA Cloud+ (CV0-004)SecurityMedium
A cloud administrator is configuring a new virtual network for a highly sensitive application. The application's backend database must only be accessible from specific application servers within the same virtual network and must not be exposed to the public internet or other segments of the organization's cloud infrastructure. Which network security construct should the administrator use to enforce this strict access control at the subnet level?
- ANetwork Access Control List (NACL)
- BCloud Firewall
- CVirtual Private Gateway
- DLoad Balancer
Show answer & explanationAnswer & explanation
Correct answer: A. Network Access Control List (NACL)
A Network Access Control List (NACL) operates at the subnet level and acts as a stateless packet filter. It can be used to explicitly allow or deny inbound and outbound traffic to and from subnets, providing granular control over network traffic flow and isolation for sensitive resources like databases.
Why the other options are wrong
- B. A Cloud Firewall (often an NGFW) typically operates at a higher level (e.g., VPC or application layer) and is stateful. While it could filter, NACLs are specifically designed for subnet-level stateless filtering.
- C. A Virtual Private Gateway is used for VPN connections between on-premises networks and cloud VPCs, not for intra-VPC subnet isolation.
- D. A Load Balancer distributes traffic, it's not primarily for subnet-level access control.
Network Access Control List (NACL)
A stateless packet filtering firewall that operates at the subnet level, controlling inbound and outbound traffic to and from one or more subnets.
- Stateless: Doesn't remember previous connections.
- Applies to all instances within a subnet.
- Rules are evaluated in order (lowest rule number first).
- Default rule denies all traffic if no other rules match (explicit deny).
Memory trick: NACLs Nuke All Connections Not Listed.