EC-Council Certified Ethical Hacker (CEH) v12Cloud ComputingMedium
A cloud administrator is configuring network security for a new application deployed in a Virtual Private Cloud (VPC). The application's web servers are in a public subnet and need to receive inbound traffic from the internet on port 443. The database servers are in a private subnet and should only allow inbound traffic from the web servers on port 3306. Which cloud network security control should be used to enforce these rules at the instance level, acting as a virtual firewall for each instance?
- AVPC Firewall
- BSecurity Group
- CNetwork Access Control List (NACL)
- DRoute Table
Show answer & explanationAnswer & explanation
Correct answer: B. Security Group
Security Groups operate at the instance level, acting as a stateful virtual firewall. They define inbound and outbound rules for network traffic for all associated instances, making them ideal for granular control over individual web and database servers.
Why the other options are wrong
- A. VPC Firewall is a generic term; in AWS, it's often implemented via Security Groups, NACLs, or specific firewall services, but 'Security Group' is the specific control for instance-level rules.
- C. NACLs operate at the subnet level, are stateless, and process rules in order, which is less granular than instance-level control.
- D. Route Tables define how network traffic is directed between subnets and to the internet, not for filtering traffic at the instance level.
Security Group (Cloud)
A virtual firewall that controls inbound and outbound traffic for one or more cloud instances.
- Operates at the instance level.
- Stateful: automatically allows return traffic for permitted outbound requests.
- Allows specifying rules based on IP address, port, and protocol.
Memory trick: Security Group: Guard at the instance's door.