Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityEasy

A cloud administrator is configuring network security for a new application deployed on multiple virtual machines (VMs) within a Virtual Private Cloud (VPC). The application requires strict inbound and outbound traffic filtering based on IP addresses, ports, and protocols for individual VMs. Which security construct is most appropriate for this granular, stateful filtering at the VM network interface level?

  1. AVPN Gateway
  2. BVPC Flow Logs
  3. CNetwork Access Control Lists (NACLs)
  4. DSecurity Groups
Show answer & explanation

Correct answer: D. Security Groups

Security Groups provide stateful packet filtering for individual VMs (or network interfaces), allowing granular control over inbound and outbound traffic based on IP addresses, ports, and protocols.

Why the other options are wrong

  • A. A VPN Gateway provides secure connectivity to on-premises networks but is not a primary tool for granular VM traffic filtering within a VPC.
  • B. VPC Flow Logs are for monitoring network traffic, not for filtering it.
  • C. NACLs are stateless and operate at the subnet level, providing less granular control than security groups.

Cloud Security Groups

A virtual firewall that controls inbound and outbound traffic for one or more virtual machines (or network interfaces) in a cloud environment.

  • Operates at the instance level.
  • Is stateful, meaning return traffic is automatically allowed.
  • Can be configured with allow rules for specific IP addresses, ports, and protocols.

Memory trick: Think of a Security Group as a personal guard for each VM, checking everyone who comes and goes. NACLs are like a gate for the whole neighborhood.

More Cloud Platform and Infrastructure Security questions