Controlling EC2 Instance Traffic with Security Groups
A company runs many Amazon EC2 instances in its VPC. The company wants to use a native AWS security resource to control network traffic between certain EC2 instances. Which AWS service or feature will meet this requirement?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question specifies controlling traffic between 'certain' instances, which requires stateful, instance-level filtering provided by security groups rather than subnet-level Network ACLs.
Security groups act as instance-level virtual firewalls to control network traffic between specific EC2 instances within a VPC.
Candidates often choose Network ACLs because they also filter traffic, but NACLs operate at the subnet level and are stateless, making them unsuitable for targeting specific instances.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Security groups are the correct choice because they function as virtual firewalls that operate at the instance level. They allow you to define rules to control inbound and outbound traffic for specific EC2 instances, enabling precise control over communication between 'certain' instances as requested.Why the Other Options Are Wrong
Network ACLs (A) operate at the subnet level, not the instance level, and are stateless, meaning they cannot easily track connections between specific pairs of instances in the same way. AWS WAF (B) is designed to protect web applications from common web exploits like SQL injection, not general EC2 instance traffic. Amazon GuardDuty (C) is a threat detection service that monitors for malicious activity but does not actively block or control network traffic flows.Community Comment Notes
Community consensus strongly supports Security Groups, with users noting the keyword 'certain' implies instance-level granularity. As one commenter noted, 'Security group is instance level; NACL is subnet level', highlighting the critical distinction in scope.Exam Strategy
When a question mentions controlling traffic for 'specific' or 'certain' resources, look for instance-level controls like Security Groups. If the requirement is broader, covering an entire subnet or CIDR range regardless of instance, consider Network ACLs.
Frequently Asked Questions
Why can't I use Network ACLs to control traffic between specific instances?
Network ACLs operate at the subnet level, applying rules to all instances within that subnet. They cannot target individual instances specifically.
What is the main difference between Security Groups and NACLs?
Security Groups are stateful and instance-level, while NACLs are stateless and subnet-level. SGs are better for fine-grained instance control.
Related Analysis
Practice All CLF-C02 Questions
Access 120 questions with complete answers and detailed explanations.
View Full CLF-C02 Practice Test →