exam questions

Exam AWS Certified Cloud Practitioner CLF-C02 All Questions

View all questions & answers for the AWS Certified Cloud Practitioner CLF-C02 exam

Exam AWS Certified Cloud Practitioner CLF-C02 topic 1 question 95 discussion

Which AWS service or tool can be used to set up a firewall to control traffic going into and coming out of an Amazon VPC subnet?

  • A. Security group
  • B. AWS WAF
  • C. AWS Firewall Manager
  • D. Network ACL
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
pietro167
Highly Voted 1 year, 4 months ago
Selected Answer: D
ACL = subnet, Security Groups = instances
upvoted 50 times
reddy187
10 months, 1 week ago
Correct : KeyWOrd: Subnet
upvoted 2 times
...
...
Penny357
Highly Voted 1 year, 4 months ago
Selected Answer: C
The Question states "AWS service or tool can be 'used' to set up a firewall" So option is C. And Network ACL is not a AWS service or tool. Correct me if i am wrong.
upvoted 10 times
nani12e434
3 months, 2 weeks ago
If the focus is solely on "setting up a firewall for a VPC subnet," Network ACLs (NACLs) are technically the mechanism you'd use. However, if the question is interpreted as "which AWS tool could manage such configurations on a broader scale," AWS Firewall Manager becomes a relevant answer.
upvoted 2 times
...
Taku2023
1 year, 2 months ago
AWS firewall Manager has nothing to do with VPC subnets
upvoted 2 times
...
BShelat
1 year, 3 months ago
You are right. NACL is a list of rules. It is not a tool "to setup and manage" firewall. AWS Firewall Manager is a tool to setup, configure and manage AWS WAF and AWS Shield .
upvoted 4 times
...
Rahul_Ghai
1 year, 3 months ago
The term Service is a broader classification. The key point is that Network Access Control List acts as a firewall to secure virtual private clouds (VPCs) and subnets. NACLs control and manage traffic in subnets
upvoted 1 times
...
...
Hokage25
Most Recent 1 month ago
Selected Answer: C
Read carefully its`s a TRAP : "control traffic going into and coming out of an Amazon VPC subnet" - NOT AT SUBNET LEVEL in my opinion it means that - control traffic at higher level that VPC subnet. My answer is C - AWS Firewall manager My explanation: network (ACL) allows or denies specific inbound or outbound traffic AT THE subnet level
upvoted 1 times
...
6ce3034
2 months ago
Selected Answer: D
The correct answer is: D. Network ACL Explanation: A Network Access Control List (Network ACL) is a security layer at the subnet level that controls inbound and outbound traffic for Amazon VPC. It acts as a firewall for controlling traffic going in and out of subnets, providing stateless filtering based on rules.
upvoted 1 times
Hokage25
1 month ago
You are wrong - read carefully question and your explanation. The trick is in the question - and coming out (of an Amazon VPC subnet) "OF AN VPC Subnet" - it means that is over subnet. As you answer - Network (ACL) - security layer (AT THE) subnet level. - it mean it is in subnet
upvoted 1 times
...
...
Smile03
3 months ago
Selected Answer: D
A: Security group acts as a virtual firewall for your EC2 instances to control incoming and outgoing traffic. Inbound rules control the incoming traffic to your instance, and outbound rules control the outgoing traffic from your instance. When you launch an instance, you can specify one or more security groups. If you don't specify a security group, Amazon EC2 uses the default security group for the VPC. After you launch an instance, you can change its security groups. C: Your VPC automatically comes with a modifiable default network ACL. By default, it allows all inbound and outbound IPv4 traffic and, if applicable, IPv6 traffic. You can create a custom network ACL and associate it with a subnet to allow or deny specific inbound or outbound traffic at the subnet level.
upvoted 1 times
...
Amin_013
4 months ago
Selected Answer: D
Network ACLs are used to control inbound and outbound traffic at the subnet level within an Amazon VPC. They provide a way to set up a firewall that operates at the network layer and are applied to all instances within a subnet.
upvoted 1 times
...
SrikanthNL
4 months, 2 weeks ago
Selected Answer: C
TOOL, FIREWALL MANAGER = TOOL and is superset of NACL
upvoted 1 times
...
ShaiTay
5 months, 2 weeks ago
Selected Answer: D
D. Network ACL - key word is subnet
upvoted 1 times
...
Kilobay1
7 months, 2 weeks ago
Selected Answer: D
Network ACLs are used to control inbound and outbound traffic at the subnet level within an Amazon VPC. They provide a way to set up a firewall that operates at the network layer and are applied to all instances within a subnet.
upvoted 1 times
...
EvilBeaver
9 months ago
Selected Answer: D
As stated in the question, we're looking for a mechanism to control the subnet traffic, so it's a NACL.
upvoted 1 times
...
ChhatwaniB
9 months, 3 weeks ago
Answer D : Network Access Control Lists (NACLs) Act as a firewall to control traffic at the subnet level, allowing or denying specific inbound or outbound traffic.
upvoted 2 times
...
geocis
10 months, 2 weeks ago
Selected Answer: D
Like Pietro167 stated Network ACL = Subnet | Security Groups = Instances
upvoted 1 times
...
Val2344
11 months, 3 weeks ago
Selected Answer: D
The correct answer is D. Network ACL (Access Control List). Network ACLs act as a firewall for controlling traffic in and out of a subnet in Amazon Virtual Private Cloud (VPC). They operate at the subnet level and evaluate traffic based on rules defined for inbound and outbound traffic.
upvoted 3 times
...
pqd
11 months, 3 weeks ago
ACL = sub-rede, grupos de segurança = instâncias (by pietro167) Perfect
upvoted 1 times
...
chalaka
1 year ago
Selected Answer: D
D. Network ACL (Access Control List) Network ACLs act as a firewall for controlling traffic at the subnet level. They are stateless and operate at the subnet level, allowing or denying traffic based on rules defined for inbound and outbound traffic. Network ACLs provide an added layer of security by allowing you to specify rules that govern traffic at the network level, complementing the security groups that operate at the instance level.
upvoted 1 times
...
Gallileo9
1 year ago
Selected Answer: D
Network ACL
upvoted 1 times
...
Nilupul21
1 year, 1 month ago
Correct answer is NACL Security Group is used for setup inbound and outbound rules in instance levels not in subnet levels. The question ask for a service or tool which serves at subnet levels. So, this answer is not correct. NACL: Allows to setup rules at subnet levels. So this is the correct answer. Firewall Manager: This is used for a broader perspective. It simplifies administration and maintenance tasks across multiple AWS accounts for variety of protections like WAF, Shield, Security Groups and Network Firewall etc.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago