A company is configuring network security controls for a web application deployed on Amazon EC2 instances within a single subnet. The security team wants to apply stateless filtering at the subnet boundary to block specific malicious IP addresses, while allowing developers to manage stateful firewall rules at the individual instance level. Which TWO of the following AWS network security features should the team configure to achieve this?
- Network Access Control Lists (Network ACLs) to enforce stateless traffic filtering at the subnet boundaryCevap
- BAWS Transit Gateway to route and inspect traffic between the subnet boundary and the EC2 instances
- Security Groups to enforce stateful traffic filtering at the EC2 instance levelCevap
- DSecurity Groups configured at the subnet boundary to perform stateless IP blocking
- ENetwork Access Control Lists (Network ACLs) configured at the EC2 instance level to manage stateful rule tracking
Cevap
Network Access Control Lists (Network ACLs) to enforce stateless traffic filtering at the subnet boundary, and Security Groups to enforce stateful traffic filtering at the EC2 instance level.
To implement stateless filtering at the subnet boundary to block malicious IPs, Network Access Control Lists (Network ACLs) must be used. To implement stateful filtering at the individual EC2 instance level, Security Groups must be used.
Adım Adım Çözüm
Anahtar Kavram
The difference between Security Groups (stateful, instance-level) and Network ACLs (stateless, subnet-level).