Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company has a VPC with multiple subnets. The security team wants to control traffic between subnets using a stateful firewall that can automatically allow return traffic. Which AWS service should be used?

⚠ Common exam trap

Test-takers frequently confuse Network ACLs with security groups, assuming both are stateful, but Network ACLs are stateless and require explicit bidirectional rules, while security groups automatically handle return traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security groups

Security groups act as a stateful virtual firewall for EC2 instances and other resources at the subnet or instance level. They automatically allow return traffic regardless of inbound or outbound rules, which satisfies the requirement for a stateful firewall that controls traffic between subnets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Network ACLs

    Why it's wrong here

    Network ACLs are stateless, so they do not automatically allow return traffic; you must explicitly configure both inbound and outbound rules for every protocol and port in each direction. They operate at the subnet boundary as a coarse filter, but their stateless nature and rule-number limits make them unsuitable for the fine-grained, connection-aware control the security team needs.

  • ✗

    AWS Firewall Manager

    Why it's wrong here

    AWS Firewall Manager is a centralized policy management service that helps enforce security rules across accounts and resources within an AWS Organization. It does not itself perform packet filtering or stateful inspection; instead, it coordinates the deployment and maintenance of AWS WAF rules, AWS Shield protections, and security groups. Therefore, it is a management overlay, not the correct tool for direct subnet-level traffic filtering.

  • ✗

    AWS WAF

    Why it's wrong here

    AWS WAF is a web application firewall that inspects HTTP/HTTPS traffic at Layer 7 to protect applications from web exploits such as SQL injection, cross-site scripting, and rule-based attacks. It attaches to Amazon CloudFront, Application Load Balancers, or API Gateway, not to subnets or VPC endpoints, so it cannot evaluate raw IP traffic between subnets.

  • ✓

    Security groups

    Why this is correct

    Security groups are stateful and are attached to elastic network interfaces (ENIs), automatically permitting return traffic without requiring separate outbound rules for responses. They can be applied consistently across all instances within a subnet to provide effective subnet-wide filtering with connection tracking, which aligns with the security team's need for granular, connection-aware traffic control. Because they operate per-interface and maintain state, they are the correct choice in this scenario.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.