Security & ComplianceQuestion 43 of 100
In a VPC, which stateful virtual firewall controls inbound and outbound traffic at the instance level?
a.Network access control list (NACL)
b.Security group
c.Internet gateway
d.Route table
Explanation
A security group acts as a stateful firewall at the instance (ENI) level, where return traffic is automatically allowed. NACLs, by contrast, are stateless firewalls that operate at the subnet level.
Practice all 100 questions free — no signup required.
Related questions on this topic
- Which service securely stores and automatically rotates database credentials, API keys, and other secrets?
- Which service scans EC2 instances and container images for software vulnerabilities and unintended network exposure?
- Which service provides sign-up, sign-in, and access control for web and mobile application users, including identity federation?
- Which statement about network ACLs (NACLs) is correct?
- A company wants to centrally manage multiple AWS accounts and apply guardrails that restrict which services accounts can use. Which combination helps?
- What does 'encryption in transit' protect?
Last reviewed: · editorial process
PrepPass Editorial Team · Verified against AWS Certified Cloud Practitioner (CLF-C02) · How we review