Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityMedium
A security architect is designing a secure cloud environment. They want to ensure that all network traffic entering and exiting their Virtual Private Cloud (VPC) is inspected and filtered based on defined rules. Which cloud security technology is best suited for this purpose at the perimeter of the VPC?
- ANetwork Access Control Lists (NACLs)
- BWeb Application Firewall (WAF)
- CIdentity and Access Management (IAM)
- DSecurity Groups
Show answer & explanationAnswer & explanation
Correct answer: A. Network Access Control Lists (NACLs)
NACLs are stateless packet filters that operate at the subnet level within a VPC. They allow or deny traffic based on IP addresses, ports, and protocols, acting as a virtual firewall for inbound and outbound traffic for an entire subnet.
Why the other options are wrong
- B. WAFs protect web applications from common web exploits, operating at the application layer (Layer 7), not the network perimeter.
- C. IAM manages user permissions and access to resources, not network traffic filtering.
- D. Security Groups are stateful firewalls that operate at the instance level, not the subnet perimeter.
Network Access Control List (NACL)
A stateless packet filtering firewall that controls traffic in and out of one or more subnets within a Virtual Private Cloud (VPC). It operates at the subnet level.
- Stateless: must explicitly allow both inbound and outbound traffic.
- Operates at the subnet level.
- Rules are evaluated in order, from lowest to highest.
Memory trick: NACLs are like 'N'etwork 'A'ir 'C'ontrol 'L'anes for your subnets.