Courseiva
Network ImplementationmediumMatchingObjective-mapped

ANS-C01 Network Implementation Practice Question

Match each AWS security feature to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Stateful firewall that controls inbound and outbound traffic at instance level

Stateless firewall that controls traffic at subnet level

Web application firewall that protects against common web exploits

Managed DDoS protection service with enhanced detection and mitigation

Managed firewall service that provides stateful inspection for VPC traffic

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Security Groups: Acts as a virtual firewall for an EC2 instance at the instance level, controlling inbound and outbound traffic.

These are core security services for network protection. Security Groups are instance-level, NACLs are subnet-level, WAF protects web apps, and Shield provides DDoS protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Security Groups: Acts as a virtual firewall for an EC2 instance at the instance level, controlling inbound and outbound traffic.

    Why this is correct

    Security Groups are stateful firewalls that operate at the instance level.

  • Network ACLs: Acts as a firewall for a VPC subnet, controlling inbound and outbound traffic at the subnet level.

    Why this is correct

    Network ACLs are stateless firewalls operating at the subnet level.

  • AWS WAF: A web application firewall that helps protect web applications from common web exploits.

    Why this is correct

    AWS WAF filters and monitors HTTP/HTTPS requests to protect web apps.

  • AWS Shield: A managed DDoS protection service that safeguards applications running on AWS.

    Why this is correct

    AWS Shield provides automatic DDoS mitigation for AWS resources.

  • Security Groups: Acts as a firewall at the subnet level.

    Why it's wrong here

    Incorrect — Security Groups operate at the instance level, not subnet. This describes Network ACLs.

  • Network ACLs: Acts as a virtual firewall for an EC2 instance.

    Why it's wrong here

    Incorrect — Network ACLs operate at the subnet level, not instance. This describes Security Groups.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This ANS-C01 question is part of Courseiva's 1,621-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.