Courseiva

SCS-C02 Management and Security Governance Practice Question

Match each AWS security control to its category.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Stateful firewall at instance level

Stateless firewall at subnet level

Centralized management of firewall rules

Managed firewall for VPCs

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security Group: A stateful firewall that controls inbound and outbound traffic at the instance level.

Security Groups are stateful instance-level firewalls, Network ACLs are stateless subnet-level firewalls. Common confusions involve mixing statefulness and level of operation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Security Group: A stateful firewall that controls inbound and outbound traffic at the instance level.

    Why this is correct

    Security groups are stateful virtual firewalls that operate at the elastic network interface (ENI) level, directly attached to EC2 instances or other VPC resources. When an inbound rule permits traffic, the corresponding outbound response is automatically allowed even if no outbound rule exists, because the security group tracks established connections. Rules are evaluated as a cumulative allow list, with an implicit deny for anything not explicitly permitted, and no explicit deny rules can be configured. This instance-level, stateful behavior is what separates security groups from stateless network ACLs at the subnet boundary.

  • ✓

    Network ACL: A stateless firewall that controls inbound and outbound traffic at the subnet level.

    Why this is correct

    A network ACL is a stateless filter associated with a VPC subnet, inspecting both inbound and outbound traffic at the boundary between the subnet and the rest of the VPC. Because it lacks connection state, every packet is evaluated independently, so you must define separate inbound and outbound rules to allow response traffic, often including ephemeral port ranges. Rules are processed in ascending numeric order, and the first rule whose criteria match dictates the allow or deny action, permitting explicit deny rules that security groups cannot express. This subnet-level, stateless scope makes NACLs a coarse-grained layer beyond instance-level security groups.

  • ✗

    Security Group: A stateless firewall that controls traffic at the subnet level.

    Why it's wrong here

    This choice incorrectly labels security groups as stateless and as a subnet-level control. A security group is inherently stateful, meaning if an inbound packet is allowed, the outbound reply is automatically permitted even without an explicit outbound rule, and it is scoped to an instance's network interface rather than an entire subnet. The characteristics described here—stateless operation and subnet-scoped evaluation—belong to a network ACL, not a security group, so this option conflates two distinct layers of VPC filtering.

  • ✗

    AWS WAF: A stateful firewall that controls traffic at the instance level.

    Why it's wrong here

    AWS WAF is a web application firewall that inspects HTTP/HTTPS traffic at Layer 7, filtering for signatures such as SQL injection, cross-site scripting, and oversized request bodies, while also supporting rate-based and bot-control rules. It is not a stateful packet-level firewall, because it does not track TCP session state or evaluate non-HTTP protocols, and it is not deployed at the instance level; instead, it is attached to CloudFront distributions, Application Load Balancers, Amazon API Gateway, or AWS App Runner. This option therefore mischaracterizes WAF's operational layer and scope, confusing it with the stateful, instance-level security group.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.