Which services can be used to block network traffic to an EC2 instance? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Security groups, Network ACLs.
Why this is the answer
Security groups act as virtual firewalls for EC2 instances, controlling inbound and outbound traffic at the instance level. They specify allowed protocols, ports, and source/destination IP ranges. Network Access Control Lists (ACLs) are stateless firewalls that operate at the subnet level within a VPC, allowing or denying traffic based on rules. Both services directly block network traffic. Amazon VPC flow logs capture information about IP traffic going to and from network interfaces in your VPC, but they do not block traffic. Amazon CloudWatch monitors AWS resources and applications, while AWS CloudTrail logs API calls and related events, neither of which block network traffic.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed