AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityEasy
A financial institution is deploying a new critical application on AWS that requires strict network isolation. The application's Amazon EC2 instances must only communicate with specific internal services (e.g., a database, a caching layer) and absolutely no other services or the internet, except for necessary OS updates from trusted sources. The security team wants to apply the principle of least privilege at the network level. Which AWS networking component should be used to achieve this granular control over traffic to and from the EC2 instances?
- ARoute Tables
- BNetwork Access Control Lists (NACLs)
- CSecurity Groups
- DVPC Flow Logs
Show answer & explanationAnswer & explanation
Correct answer: C. Security Groups
Security Groups operate at the instance level and act as a stateful firewall, allowing granular control over inbound and outbound traffic to and from EC2 instances. They are ideal for implementing the principle of least privilege at the network level, specifying exactly which ports and protocols are allowed between instances and specific services.
Why the other options are wrong
- A. Route Tables define how network traffic is directed between subnets, gateways, and other network destinations, but they do not filter traffic at the instance level based on ports or protocols.
- B. NACLs operate at the subnet level, are stateless, and are less granular than Security Groups, making them less suitable for instance-specific least privilege control.
- D. VPC Flow Logs are for monitoring and logging network traffic, not for controlling it.
AWS Security Groups
A virtual firewall for your EC2 instances to control inbound and outbound traffic. Security groups act at the instance level, not the subnet level, and are stateful.
- Act as a stateful firewall for EC2 instances.
- Control inbound and outbound traffic based on rules (protocol, port, source/destination).
- Apply at the instance level, not the subnet level.
- All inbound traffic is denied by default; all outbound traffic is allowed by default.
Memory trick: Security Groups are like the 'personal bodyguards' for each EC2 instance.