Which AWS feature acts as a virtual firewall applied at the VPC subnet level?
Choose an answer
Tap an option to check your answer.
Correct answer: Network ACL.
Why this is the answer
A Network Access Control List (NACL) is a stateless firewall that operates at the subnet level within a Virtual Private Cloud (VPC). It evaluates rules in order from lowest to highest and applies to all instances within the subnet. Security groups are stateful firewalls that operate at the instance level. Traffic Mirroring is used to copy network traffic to an analysis tool, not for filtering. An Internet gateway connects a VPC to the internet.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed