After launching an EC2 instance, which AWS resource should be used to control inbound and outbound network traffic at the instance level?
Choose an answer
Tap an option to check your answer.
Correct answer: Security groups.
Why this is the answer
Security groups act as virtual firewalls for EC2 instances, controlling both inbound and outbound traffic at the instance level. They specify allowed protocols, ports, and source/destination IP addresses, ensuring only authorized traffic reaches or leaves the instance. AWS Shield is a managed Distributed Denial of Service (DDoS) protection service, not a firewall for individual instances. Network Access Analyzer helps identify unintended network access to your resources but doesn't actively control traffic. VPC endpoints allow private connections to AWS services without traversing the internet, but they don't function as traffic filters for EC2 instances.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed