Which native AWS capability allows control of network traffic between specific EC2 instances within a VPC?
Choose an answer
Tap an option to check your answer.
Correct answer: Security groups.
Why this is the answer
Security groups act as virtual firewalls for EC2 instances, controlling inbound and outbound traffic at the instance level. They allow you to specify rules for protocols, port ranges, and source/destination IP addresses or other security groups, enabling fine-grained control between specific instances within a VPC. Network ACLs (NACLs) operate at the subnet level, controlling traffic for all instances within a subnet. While they also filter traffic, they are stateless and less granular than security groups for instance-to-instance communication. AWS WAF (Web Application Firewall) protects web applications from common web exploits, not general network traffic between EC2 instances. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, rather than controlling traffic flow.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed