Which AWS service or feature can be used to enforce security rules that apply to individual Amazon EC2 instances?
Choose an answer
Tap an option to check your answer.
Correct answer: Security groups.
Why this is the answer
Security groups act as virtual firewalls for EC2 instances, controlling inbound and outbound traffic at the instance level. They allow you to specify protocols, port ranges, and source/destination IP addresses or other security groups, enforcing granular security rules for individual instances. Network ACLs operate at the subnet level, controlling traffic for all instances within a subnet, not individual instances. AWS Trusted Advisor provides recommendations for cost optimization, performance, security, and fault tolerance, but it does not enforce security rules. AWS WAF (Web Application Firewall) protects web applications from common web exploits, operating at the application layer, not directly on individual EC2 instances.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed