AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityEasy
A financial institution is deploying a new critical application on AWS that requires strict network isolation and the ability to control all inbound and outbound traffic at a granular level for specific IP addresses and ports. The application will run on Amazon EC2 instances within a Virtual Private Cloud (VPC). Which AWS networking construct should be used to provide the most granular, instance-level control over network traffic for these EC2 instances?
- ANetwork Access Control Lists (NACLs) associated with the subnets.
- BAWS WAF rules applied to an Application Load Balancer.
- CSecurity Groups associated with the EC2 instances.
- DVPC Flow Logs enabled for the VPC.
Show answer & explanationAnswer & explanation
Correct answer: C. Security Groups associated with the EC2 instances.
Security Groups operate at the instance level and allow for granular control of inbound and outbound traffic, making them ideal for specific IP address and port requirements for individual EC2 instances. They act as a virtual firewall for your instances.
Why the other options are wrong
- A. NACLs operate at the subnet level and are stateless, making them less granular for instance-specific control.
- B. AWS WAF protects web applications at the application layer, not individual EC2 instance network traffic.
- D. VPC Flow Logs are for monitoring network traffic, not controlling it.
Security Groups
Security Groups act as a virtual firewall for your EC2 instances to control inbound and outbound traffic. They operate at the instance level.
- Stateful: automatically allows return traffic.
- Operate at the instance level.
- Allow or deny based on IP, port, and protocol.
Memory trick: Security Groups Guard Instances, NACLs Nurture Subnets.