AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceEasy

A financial services company is migrating a legacy application to AWS. The application requires strict network segmentation and stateful packet inspection at the subnet level within a VPC. Which AWS networking construct should be used to meet these requirements?

  1. AAWS WAF
  2. BVPC Flow Logs
  3. CNetwork Access Control Lists (NACLs)
  4. DSecurity Groups
Show answer & explanation

Correct answer: C. Network Access Control Lists (NACLs)

NACLs provide stateless packet filtering at the subnet level, allowing or denying traffic based on rules. While they are stateless, they operate at the subnet boundary to enforce segmentation.

Why the other options are wrong

  • A. AWS WAF operates at the application layer to protect web applications, not at the network layer for subnet segmentation.
  • B. VPC Flow Logs capture IP traffic information but do not provide any filtering or segmentation capabilities.
  • D. Security Groups provide stateful filtering at the instance level, not the subnet level.

Network Access Control List (NACL)

A stateless firewall that controls traffic in and out of one or more subnets.

  • Operates at the subnet level.
  • Stateless: separate inbound and outbound rules.
  • Rules are evaluated in order, from lowest to highest.
  • Default NACL allows all traffic.

Memory trick: NACLs control traffic at the subnet's gate, stateless but always check the date.

More Network Security, Compliance, and Governance questions