Question 1 · choose 2
A team is comparing security groups and network ACLs in its VPC. Which statements describe security groups? (Choose TWO.)
- AThey evaluate rules in number order and stop at the first match
- BThey can contain rules that explicitly deny traffic
- CThey are stateful, so the response to allowed traffic is allowed automatically
- DThey are associated with subnets, and each subnet has exactly one
- EThey operate at the instance level and apply to the resources associated with them
Show the answer and why
AThey evaluate rules in number order and stop at the first match
Incorrect
That is how a network ACL works. A security group evaluates all of its rules before deciding whether to allow traffic.
BThey can contain rules that explicitly deny traffic
Incorrect
Security groups have allow rules only. Explicit deny rules are a network ACL feature.
CThey are stateful, so the response to allowed traffic is allowed automatically
Correct
Security groups are stateful: return traffic is automatically allowed, whatever the rules in the other direction say.
DThey are associated with subnets, and each subnet has exactly one
Incorrect
Every subnet is associated with exactly one network ACL. Security groups are associated with resources, and a resource can have several.
EThey operate at the instance level and apply to the resources associated with them
Correct
A security group controls the traffic allowed to reach and leave the resources it is associated with, such as an EC2 instance.
Security group: instance level, allow rules only, all rules evaluated, stateful. Network ACL: subnet level, allow and deny, numbered order, stateless.
AWS documentation