AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityEasy

A financial institution is deploying a new critical application on AWS that requires strict network isolation and granular control over inbound and outbound traffic for its Amazon EC2 instances. The security team mandates that all instances must only communicate with explicitly allowed resources and that any unauthorized access attempts must be blocked at the instance level. Which AWS service or feature should be primarily used to meet these requirements for network traffic filtering?

  1. AAmazon VPC Flow Logs
  2. BAWS Network Access Control Lists (NACLs)
  3. CAWS Security Groups
  4. DAWS WAF (Web Application Firewall)
Show answer & explanation

Correct answer: C. AWS Security Groups

Security Groups provide stateful, instance-level network filtering, making them ideal for granular control over inbound and outbound traffic to EC2 instances. They allow specifying explicit rules for allowed communication, blocking all other traffic by default.

Why the other options are wrong

  • A. VPC Flow Logs capture information about IP traffic going to and from network interfaces, but they are a monitoring tool, not a traffic filtering or blocking service.
  • B. NACLs are stateless, operate at the subnet level, and are less granular than security groups for instance-specific traffic control.
  • D. AWS WAF protects against web application exploits at the application layer (Layer 7) and is not designed for instance-level network traffic filtering.

AWS Security Groups

AWS Security Groups act as a virtual firewall for your EC2 instances to control inbound and outbound traffic. They are stateful and operate at the instance level.

  • Stateful: automatically allows return traffic for allowed outbound connections.
  • Instance-level filtering: applies to one or more EC2 instances.
  • Allows rules: you define rules for allowed traffic; everything else is implicitly denied.
  • Supports both IPv4 and IPv6.

Memory trick: Security Groups are like bouncers for your EC2 club, checking IDs and allowing only approved guests in and out, remembering who's already inside.

More Domain 3: Infrastructure Security questions