Which of these are characteristics of network access control lists (network ACLs) in AWS? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: They are stateless., They evaluate rules in numerical order, starting with the lowest rule number, to decide whether to allow traffic..
Why this is the answer
Network ACLs are stateless, meaning they do not remember previous connections. For example, if you allow inbound traffic on port 80, you must explicitly allow outbound return traffic on ephemeral ports. This contrasts with security groups, which are stateful. Network ACLs evaluate rules in numerical order, from the lowest number to the highest, and stop evaluating once a rule is matched. This ordered evaluation is crucial for defining specific traffic flow policies. They apply at the subnet level, not the instance level, protecting all instances within a subnet. Security groups, conversely, apply at the instance level.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed