CLF-C02 Security and Compliance Practice Question
A security engineer needs to apply network traffic filtering rules at the subnet level rather than the instance level. The solution must be stateless and must explicitly define both inbound and outbound rules, including allowing return traffic. Which AWS feature provides subnet-level stateless traffic control?
⚠ Common exam trap
Many candidates confuse security groups (stateful, instance-level) with NACLs (stateless, subnet-level), forgetting that the stateless requirement explicitly demands separate inbound and outbound rules for return traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Network Access Control Lists (NACLs)
Network Access Control Lists (NACLs) are the correct choice because they operate at the subnet level, are stateless (meaning they do not automatically allow return traffic), and require explicit inbound and outbound rules. This matches the requirement for stateless traffic filtering where both directions must be defined separately, including rules for return traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security groups
Why it's wrong here
Security groups are stateful, so if an inbound request is allowed, the outbound return traffic is automatically permitted without an explicit rule. They attach at the instance or Elastic Network Interface (ENI) level, not at the subnet boundary, and therefore cannot serve as a subnet-level firewall. This stateful behavior and instance-scoped association distinguish them from NACLs, which must define both inbound and outbound rules for the entire subnet.
- ✓
Network Access Control Lists (NACLs)
Why this is correct
NACLs are applied at the subnet level and are stateless — each packet is evaluated against the rules independently. Both inbound and outbound rules must explicitly allow traffic, including return traffic for connections initiated from inside the subnet.
- ✗
AWS WAF
Why it's wrong here
AWS WAF is a web application firewall that inspects HTTP/HTTPS traffic for common attack patterns like SQL injection and cross-site scripting. It is typically attached to application delivery services such as Application Load Balancer, CloudFront, or API Gateway, not to VPC subnets. Because it operates at Layer 7 and only evaluates web requests, it cannot filter raw TCP/IP packets at the subnet level like a stateless NACL.
- ✗
VPC route tables
Why it's wrong here
VPC route tables define the next hop for traffic within or leaving a subnet, such as the internet gateway, virtual private gateway, or NAT device, but they do not contain allow/deny rules. They lack any notion of ports, protocols, or statefulness, so they cannot inspect or block packets. Routing determines path, while NACLs determine whether a packet is permitted to traverse the subnet boundary at all.
Visual reference
Go deeper
Related to this question
About these practice questions
This CLF-C02 question is part of Courseiva's 993-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.