Limiting Network Access at Subnet Level in AWS

Answer Correct answer: C — Network ACL is the AWS feature configured to limit network access at the subnet level.

Which AWS service or feature can a user configure to limit network access at the subnet level?

  1. AWS Shield
  2. AWS WAF
  3. Network ACL Correct Answer
  4. Security group

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests knowledge of perimeter security layers, with the common trap being the confusion between instance-level (Security Group) and subnet-level (Network ACL) controls.

This page clarifies the distinction between Security Groups and Network ACLs, establishing that Network ACLs are the correct feature for controlling network access at the subnet level.

Many users incorrectly select Security Group because it is more commonly used; however, Security Groups operate at the instance level, not the subnet level.

Community Discussion (3 comments)

ShaiTay 👍 1 Selected: C
C. Network ACL
2dd0f97 👍 1 Selected: C
Subnet is the keyword
DigitalSolutionsArchitect 👍 1 Selected: C
AWS Shield protects from DDos attacks AWS WAF protects from SQL injections Security groups are used at the EC2 instance level

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Network ACLs (Access Control Lists) are stateless virtual firewalls that operate at the subnet level in AWS VPCs. They allow you to explicitly permit or deny inbound and outbound traffic based on rules involving protocol, port number range, and source/destination IP addresses. Since the question specifically asks for a configuration that limits access at the subnet level, Network ACL is the technically accurate answer.

Why the Other Options Are Wrong

AWS Shield (A) provides protection against DDoS attacks but does not configure granular network access rules. AWS WAF (B) operates at the application layer (Layer 7) to protect web applications from exploits like SQL injection, not at the network/subnet level. Security Groups (D) are often confused here, but they function as stateful firewalls attached directly to Elastic Network Interfaces (ENIs), effectively operating at the instance level, not the subnet level.

Community Comment Notes

The community consensus strongly supports this logic. As DigitalSolutionsArchitec noted, "Security groups are used at the EC2 instance level," highlighting the key differentiator. Another user pointed out that "Subnet is the keyword," reinforcing that the scope of the control dictates the correct service choice.

Exam Strategy

When answering questions about network security, always check the 'scope' first. If the question mentions 'Instance', think Security Groups. If it mentions 'Subnet', think Network ACLs. This distinction is a frequent exam topic.

Frequently Asked Questions

Why isn't Security Group the answer?

Security Groups are stateful and operate at the instance level (ENI), whereas the question specifically requires subnet-level control.

What is the difference between NACL and Security Group?

NACLs are stateless and work at the subnet level, while Security Groups are stateful and work at the instance level.

More CLF-C02 FAQ →

Related Analysis

Practice All CLF-C02 Questions

Access 120 questions with complete answers and detailed explanations.

View Full CLF-C02 Practice Test →

← Back to CLF-C02 Study Guide