Which AWS feature can you use to establish a firewall that controls traffic entering and leaving an Amazon VPC subnet?
Choose an answer
Tap an option to check your answer.
Correct answer: Network ACL.
Why this is the answer
A Network Access Control List (NACL) is a stateless firewall that controls traffic at the subnet level. It allows or denies traffic based on rules you define, applying to all instances within the subnet. NACLs are stateless because they do not remember previous connections; both inbound and outbound rules must be explicitly defined. Security groups are stateful firewalls that control traffic at the instance level. AWS WAF (Web Application Firewall) protects web applications from common web exploits at the application layer. AWS Firewall Manager simplifies the administration and maintenance of firewall rules across multiple accounts and resources.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed