Soru

Zorluk: KolayNetwork and Infrastructure Security

A cloud practitioner is planning the network security layout for an Amazon VPC. Which two of the following statements correctly describe the characteristics of security groups and Network Access Control Lists (NACLs)?

  1. Security groups are stateful, meaning return traffic is automatically allowed regardless of outbound rules.Cevap
  2. Network ACLs operate at the subnet level and act as a firewall for controlling traffic entering and leaving one or more subnets.Cevap
  3. C
    Security groups operate at the subnet level to protect all resources residing within that subnet.
  4. D
    Network ACLs are stateful, meaning any allowed inbound traffic is automatically permitted to flow outbound.
  5. E
    AWS automatically configures and manages custom rules for both security groups and network ACLs under the Shared Responsibility Model.

Cevap

Security groups are stateful (inbound allowed traffic automatically allows return traffic) and Network ACLs operate at the subnet level as a firewall.
The correct options are that security groups are stateful (allowing return traffic automatically) and Network ACLs operate at the subnet boundary as firewalls. These represent the standard configuration and operational boundaries for VPC network security.

Adım Adım Çözüm

1
Analyze the characteristics of security groups.
Identify that security groups operate at the instance level and are stateful, which means they automatically allow return traffic.
This helps evaluate the options regarding security group scope and statefulness.
2
Analyze the characteristics of Network Access Control Lists (NACLs).
Identify that Network ACLs operate at the subnet level and are stateless, requiring explicit rules for both inbound and outbound traffic.
This helps evaluate the options regarding Network ACL scope and statefulness.
3
Evaluate the option related to the Shared Responsibility Model.
Recognize that network configuration, including security groups and NACL rules, is a customer responsibility.
This eliminates the distractor proposing that AWS manages these custom rules.

Anahtar Kavram

Understanding the difference between stateful security groups (instance-level) and stateless Network ACLs (subnet-level), and the customer responsibility for network security configuration.
Bu soruyu puanla