AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationEasy
A solutions architect is designing a new VPC for a critical application that requires strict inbound and outbound traffic filtering at the subnet level. The application will run on EC2 instances within private subnets. Which AWS networking construct should the architect primarily use to achieve this granular subnet-level traffic control?
- ANetwork Access Control Lists (Network ACLs)
- BAWS WAF
- CSecurity Groups
- DVPC Flow Logs
Show answer & explanationAnswer & explanation
Correct answer: A. Network Access Control Lists (Network ACLs)
Network ACLs operate at the subnet level and provide stateless packet filtering for both inbound and outbound traffic, making them ideal for granular subnet-level control. Security Groups operate at the instance level and are stateful.
Why the other options are wrong
- B. AWS WAF is a web application firewall that protects against common web exploits at the application layer, not for subnet-level traffic filtering.
- C. Security Groups are stateful and operate at the instance level, not the subnet level.
- D. VPC Flow Logs are for monitoring network traffic, not controlling it.
Network Access Control List (NACL)
A Network Access Control List (NACL) is a stateless firewall that controls traffic in and out of one or more subnets.
- Operates at the subnet level
- Stateless (separate rules for inbound and outbound)
- Allows or denies specific IP addresses, ports, and protocols
- Rules are evaluated in order, from lowest to highest
Memory trick: ACLs are like traffic cops for subnets, Security Groups are bouncers for instances.