The company requires a firewall that controls network traffic to and from a single Amazon EC2 instance, without affecting other instances in the same subnet. Which AWS feature meets this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Security group.
Why this is the answer
A security group acts as a virtual firewall for your EC2 instances, controlling inbound and outbound traffic at the instance level. This allows you to define specific rules for a single instance without impacting others in the same subnet, directly addressing the requirement. Network ACLs operate at the subnet level, applying rules to all instances within that subnet, which would affect other instances. AWS WAF (Web Application Firewall) protects web applications from common web exploits, not individual EC2 instance traffic. A route table dictates where network traffic is directed, not whether it's allowed or denied to an instance.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed