Security & ComplianceQuestion 44 of 100

Which statement about network ACLs (NACLs) is correct?

a.They are attached directly to individual instances
b.They are stateful and automatically allow return traffic
c.They can only allow traffic and never deny it
d.They are stateless and operate at the subnet level with allow and deny rules

Explanation

NACLs are stateless firewalls that operate at the subnet boundary and support both allow and deny rules, evaluated in order. Because they are stateless, you must explicitly allow both request and response traffic.

Practice all 100 questions free — no signup required.

Related questions on this topic

Last reviewed: · editorial process

PrepPass Editorial Team · Verified against AWS Certified Cloud Practitioner (CLF-C02) · How we review
Report