Drag a concept onto its matching description — or click a concept then click the description.
Stateful firewall at instance level
Stateless firewall at subnet level
Centralized management of firewall rules
Managed firewall for VPCs
Match each AWS security control to its category.
Drag a concept onto its matching description — or click a concept then click the description.
Stateful firewall at instance level
Stateless firewall at subnet level
Centralized management of firewall rules
Managed firewall for VPCs
Answer choices
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Security Group: A stateful firewall that controls inbound and outbound traffic at the instance level.
Security Groups are stateful instance-level firewalls, Network ACLs are stateless subnet-level firewalls. Common confusions involve mixing statefulness and level of operation.
Answer analysis
For each option: why learners choose it and why it is or isn't the right answer here.
Security Group: A stateful firewall that controls inbound and outbound traffic at the instance level.
Why this is correct
Security groups are stateful virtual firewalls that operate at the elastic network interface (ENI) level, directly attached to EC2 instances or other VPC resources. When an inbound rule permits traffic, the corresponding outbound response is automatically allowed even if no outbound rule exists, because the security group tracks established connections. Rules are evaluated as a cumulative allow list, with an implicit deny for anything not explicitly permitted, and no explicit deny rules can be configured. This instance-level, stateful behavior is what separates security groups from stateless network ACLs at the subnet boundary.
Network ACL: A stateless firewall that controls inbound and outbound traffic at the subnet level.
Why this is correct
A network ACL is a stateless filter associated with a VPC subnet, inspecting both inbound and outbound traffic at the boundary between the subnet and the rest of the VPC. Because it lacks connection state, every packet is evaluated independently, so you must define separate inbound and outbound rules to allow response traffic, often including ephemeral port ranges. Rules are processed in ascending numeric order, and the first rule whose criteria match dictates the allow or deny action, permitting explicit deny rules that security groups cannot express. This subnet-level, stateless scope makes NACLs a coarse-grained layer beyond instance-level security groups.
Security Group: A stateless firewall that controls traffic at the subnet level.
Why it's wrong here
This choice incorrectly labels security groups as stateless and as a subnet-level control. A security group is inherently stateful, meaning if an inbound packet is allowed, the outbound reply is automatically permitted even without an explicit outbound rule, and it is scoped to an instance's network interface rather than an entire subnet. The characteristics described here—stateless operation and subnet-scoped evaluation—belong to a network ACL, not a security group, so this option conflates two distinct layers of VPC filtering.
AWS WAF: A stateful firewall that controls traffic at the instance level.
Why it's wrong here
AWS WAF is a web application firewall that inspects HTTP/HTTPS traffic at Layer 7, filtering for signatures such as SQL injection, cross-site scripting, and oversized request bodies, while also supporting rate-based and bot-control rules. It is not a stateful packet-level firewall, because it does not track TCP session state or evaluate non-HTTP protocols, and it is not deployed at the instance level; instead, it is attached to CloudFront distributions, Application Load Balancers, Amazon API Gateway, or AWS App Runner. This option therefore mischaracterizes WAF's operational layer and scope, confusing it with the stateful, instance-level security group.
Visual reference
Go deeper
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.