AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceEasy
A software company operates a highly sensitive application on AWS. They need to ensure that all network traffic between their application servers (EC2 instances) and their database servers (EC2 instances) within the same VPC is strictly controlled at the instance level. Specifically, they want to allow only necessary ports and protocols between these tiers and deny all other traffic by default. Which AWS security construct provides this granular, stateful filtering capability at the instance level?
- ANetwork ACLs
- BAWS Network Firewall
- CSecurity Groups
- DVPC Flow Logs
Show answer & explanationAnswer & explanation
Correct answer: C. Security Groups
Security Groups provide stateful packet filtering at the instance level. They allow you to control inbound and outbound traffic for EC2 instances, enabling you to specify allowed ports, protocols, and source/destination IP ranges (or other security groups), meeting the requirement for granular, instance-level control and denying all other traffic by default.
Why the other options are wrong
- A. Network ACLs provide stateless packet filtering at the subnet level, not instance level, and allow/deny rules are evaluated independently for inbound and outbound traffic.
- B. AWS Network Firewall provides centralized, managed network threat protection for VPCs, but Security Groups are used for granular instance-level control.
- D. VPC Flow Logs capture information about IP traffic going to and from network interfaces, but they do not provide any filtering or control capabilities.
Security Groups
Virtual firewalls that control inbound and outbound traffic for your Amazon EC2 instances.
- Operate at the instance level.
- Are stateful (return traffic is automatically allowed).
- Deny all inbound traffic by default; allow all outbound by default.
Memory trick: SECURITY GROUPS guard the 'INSTANCE', NACLs guard the 'SUB-NET'.