Limiting Network Access at Subnet Level in AWS
Which AWS service or feature can a user configure to limit network access at the subnet level?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests knowledge of perimeter security layers, with the common trap being the confusion between instance-level (Security Group) and subnet-level (Network ACL) controls.
This page clarifies the distinction between Security Groups and Network ACLs, establishing that Network ACLs are the correct feature for controlling network access at the subnet level.
Many users incorrectly select Security Group because it is more commonly used; however, Security Groups operate at the instance level, not the subnet level.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Network ACLs (Access Control Lists) are stateless virtual firewalls that operate at the subnet level in AWS VPCs. They allow you to explicitly permit or deny inbound and outbound traffic based on rules involving protocol, port number range, and source/destination IP addresses. Since the question specifically asks for a configuration that limits access at the subnet level, Network ACL is the technically accurate answer.Why the Other Options Are Wrong
AWS Shield (A) provides protection against DDoS attacks but does not configure granular network access rules. AWS WAF (B) operates at the application layer (Layer 7) to protect web applications from exploits like SQL injection, not at the network/subnet level. Security Groups (D) are often confused here, but they function as stateful firewalls attached directly to Elastic Network Interfaces (ENIs), effectively operating at the instance level, not the subnet level.Community Comment Notes
The community consensus strongly supports this logic. As DigitalSolutionsArchitec noted, "Security groups are used at the EC2 instance level," highlighting the key differentiator. Another user pointed out that "Subnet is the keyword," reinforcing that the scope of the control dictates the correct service choice.Exam Strategy
When answering questions about network security, always check the 'scope' first. If the question mentions 'Instance', think Security Groups. If it mentions 'Subnet', think Network ACLs. This distinction is a frequent exam topic.
Frequently Asked Questions
Why isn't Security Group the answer?
Security Groups are stateful and operate at the instance level (ENI), whereas the question specifically requires subnet-level control.
What is the difference between NACL and Security Group?
NACLs are stateless and work at the subnet level, while Security Groups are stateful and work at the instance level.
Related Analysis
Practice All CLF-C02 Questions
Access 120 questions with complete answers and detailed explanations.
View Full CLF-C02 Practice Test →