Controlling EC2 Instance Traffic with Security Groups

Answer Correct answer: D — Use Security groups to create a virtual firewall that controls inbound and outbound network traffic for specific EC2 instances.

A company runs many Amazon EC2 instances in its VPC. The company wants to use a native AWS security resource to control network traffic between certain EC2 instances. Which AWS service or feature will meet this requirement?

  1. Network ACLs
  2. AWS WAF
  3. Amazon GuardDuty
  4. Security groups Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question specifies controlling traffic between 'certain' instances, which requires stateful, instance-level filtering provided by security groups rather than subnet-level Network ACLs.

Security groups act as instance-level virtual firewalls to control network traffic between specific EC2 instances within a VPC.

Candidates often choose Network ACLs because they also filter traffic, but NACLs operate at the subnet level and are stateless, making them unsuitable for targeting specific instances.

Community Discussion (4 comments)

femzy 👍 1 Selected: D
Security groups... keyword is "certain"
123asdzxcxza 👍 1 Selected: D
D, security group is instance level; NACL is subnet level
ShaiTay 👍 1 Selected: D
D. Security groups
e59311f 👍 1 Selected: D
The correct answer is D. Security groups. Security groups act as a virtual firewall that controls inbound and outbound traffic for EC2 instances within a subnet1. You can configure rules in security groups to allow only the minimum required network traffic, such as allowing traffic from specific IP address ranges or specific protocols like HTTPS2. If you need to control network traffic between certain EC2 instances, security groups are the appropriate choice.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Security groups are the correct choice because they function as virtual firewalls that operate at the instance level. They allow you to define rules to control inbound and outbound traffic for specific EC2 instances, enabling precise control over communication between 'certain' instances as requested.

Why the Other Options Are Wrong

Network ACLs (A) operate at the subnet level, not the instance level, and are stateless, meaning they cannot easily track connections between specific pairs of instances in the same way. AWS WAF (B) is designed to protect web applications from common web exploits like SQL injection, not general EC2 instance traffic. Amazon GuardDuty (C) is a threat detection service that monitors for malicious activity but does not actively block or control network traffic flows.

Community Comment Notes

Community consensus strongly supports Security Groups, with users noting the keyword 'certain' implies instance-level granularity. As one commenter noted, 'Security group is instance level; NACL is subnet level', highlighting the critical distinction in scope.

Exam Strategy

When a question mentions controlling traffic for 'specific' or 'certain' resources, look for instance-level controls like Security Groups. If the requirement is broader, covering an entire subnet or CIDR range regardless of instance, consider Network ACLs.

Frequently Asked Questions

Why can't I use Network ACLs to control traffic between specific instances?

Network ACLs operate at the subnet level, applying rules to all instances within that subnet. They cannot target individual instances specifically.

What is the main difference between Security Groups and NACLs?

Security Groups are stateful and instance-level, while NACLs are stateless and subnet-level. SGs are better for fine-grained instance control.

More CLF-C02 FAQ →

Related Analysis

Practice All CLF-C02 Questions

Access 120 questions with complete answers and detailed explanations.

View Full CLF-C02 Practice Test →

← Back to CLF-C02 Study Guide