Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityHard

A cloud security engineer is tasked with securing an application that handles highly sensitive financial transactions. The application is deployed on virtual machines in a public cloud. The engineer needs to implement network security controls that can filter traffic based on source IP, destination IP, port, and protocol, and apply these rules at the subnet level, acting as a stateless packet filter. Which cloud security technology fits this description?

  1. ASecurity Group
  2. BWeb Application Firewall (WAF)
  3. CVirtual Private Network (VPN)
  4. DNetwork Access Control List (NACL)
Show answer & explanation

Correct answer: D. Network Access Control List (NACL)

A Network Access Control List (NACL) operates at the subnet level, is stateless (meaning it doesn't track connection state), and filters traffic based on IP, port, and protocol. This precisely matches the described requirements for a stateless packet filter at the subnet level.

Why the other options are wrong

  • A. Security Groups are stateful and operate at the instance level, not stateless at the subnet level.
  • B. WAFs protect web applications at the application layer (Layer 7), not as a stateless packet filter at the subnet level.
  • C. VPNs provide secure, encrypted connections, but are not primarily a stateless packet filtering mechanism for internal subnet traffic.

Network Access Control List (NACL)

A stateless network security control that operates at the subnet level to filter inbound and outbound traffic based on IP addresses, ports, and protocols.

  • Stateless (separate rules for inbound/outbound)
  • Operates at the subnet level
  • Evaluates rules in order (lowest number first)

Memory trick: NACLs are like strict security guards at each subnet's border.

More Cloud Security questions