Which VPC component provides a virtual firewall that controls traffic at the Amazon EC2 instance level?
Choose an answer
Tap an option to check your answer.
Correct answer: Security group.
Why this is the answer
A security group acts as a virtual firewall for your Amazon EC2 instances, controlling inbound and outbound traffic at the instance level. It specifies allowed protocols, ports, and source/destination IP ranges. When you launch an instance, you associate one or more security groups with it. Network ACLs (Access Control Lists) are stateless firewalls that operate at the subnet level, controlling traffic for all instances within a subnet. Route tables determine where network traffic from your subnet or gateway is directed. A NAT gateway allows instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating connections with those instances.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed