Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityMedium
A cloud security engineer needs to configure network access for a group of virtual machines (VMs) that are part of a web application tier. These VMs should only accept inbound HTTP (port 80) and HTTPS (port 443) traffic from the internet and outbound traffic to a database tier (port 3306) within the same VPC. Which cloud networking construct is BEST suited for defining these stateful, instance-level rules?
- AVPC Flow Logs
- BRoute Tables
- CNetwork Access Control Lists (NACLs)
- DSecurity Groups
Show answer & explanationAnswer & explanation
Correct answer: D. Security Groups
Security Groups are stateful, instance-level virtual firewalls that control inbound and outbound traffic. They are ideal for specifying granular rules like allowing specific ports from the internet (inbound) and to specific internal resources (outbound) for a group of VMs.
Why the other options are wrong
- A. VPC Flow Logs record network traffic but do not enforce security rules or filter traffic.
- B. Route Tables define how network traffic is directed between subnets or to gateways, not for filtering traffic based on ports and protocols.
- C. NACLs are stateless, subnet-level firewalls, less granular and more complex to manage for instance-level stateful rules.
Cloud Security Groups
Virtual, stateful firewalls that control inbound and outbound network traffic for one or more virtual machines or network interfaces within a cloud VPC.
- Operate at the instance level.
- Are stateful, meaning return traffic is automatically allowed.
- Often the first line of network defense for cloud instances.
Memory trick: Groups guard instances, NACLs guard subnets.