Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityMedium

A cloud security engineer is tasked with securing an application that handles highly sensitive payment information. The application runs on virtual machines within a public cloud VPC. The engineer needs to implement stateless, packet-filtering rules to control inbound and outbound traffic at the subnet level, specifically allowing only necessary ports for the application and blocking all other traffic. Which cloud security control is most appropriate for this requirement?

  1. ANetwork Access Control List (NACL)
  2. BWeb Application Firewall (WAF)
  3. CHost-based Firewall
  4. DSecurity Groups
Show answer & explanation

Correct answer: A. Network Access Control List (NACL)

Network Access Control Lists (NACLs) are stateless, subnet-level firewalls that allow or deny inbound and outbound traffic based on IP addresses, protocols, and port numbers. They are ideal for broad traffic filtering at the subnet boundary, as described in the scenario.

Why the other options are wrong

  • B. WAFs operate at the application layer and protect against web exploits, not general packet filtering at the subnet level.
  • C. Host-based firewalls run on individual virtual machines, not at the subnet level as required.
  • D. Security Groups are stateful, instance-level firewalls, which is different from the subnet-level, stateless requirement.

Network Access Control List (NACL)

A stateless, optional layer of security for a VPC that acts as a firewall for controlling traffic in and out of one or more subnets.

  • Stateless (separate rules for inbound/outbound)
  • Applies to subnets
  • Processes rules in order (lowest number first)

Memory trick: NACL: No Acknowledgment, Controls the Lane.

More Cloud Security questions