Which AWS feature can be configured to restrict network access at the subnet level?
Choose an answer
Tap an option to check your answer.
Correct answer: Network ACL.
Why this is the answer
Network Access Control Lists (Network ACLs) operate at the subnet level, providing stateless packet filtering for all traffic entering or leaving the subnet. This allows you to define rules to explicitly allow or deny traffic based on IP addresses, ports, and protocols. AWS Shield provides DDoS protection, operating at a higher level than subnet-specific access. AWS WAF (Web Application Firewall) protects web applications from common web exploits, operating at the application layer, not the network subnet level. Security groups act as virtual firewalls for individual EC2 instances, providing stateful packet filtering at the instance level, not the subnet level.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed