SOA-C02 Networking and Content Delivery Practice Question
Which TWO AWS services can be used to improve the security of a VPC? (Choose TWO.)
⚠ Common exam trap
It's easy for candidates to confuse routing components (Internet Gateway, Route Tables, VPC Peering) with security components, assuming any VPC construct that controls traffic flow also provides security filtering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security Groups
Security Groups (A) act as a virtual firewall for instances, controlling inbound and outbound traffic at the instance level based on allow rules only. Network ACLs (D) provide a stateless firewall layer at the subnet level, supporting both allow and deny rules, and are evaluated in numeric order. Together, they offer defense-in-depth for VPC traffic filtering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security Groups
Why this is correct
Security Groups are stateful virtual firewalls that operate at the ENI/instance level within a VPC. They evaluate all inbound and outbound traffic against a set of allow rules only—there is no explicit deny rule—and return traffic is automatically permitted regardless of the outbound rule configuration. For example, if you allow inbound HTTP from 0.0.0.0/0, the corresponding outbound response traffic is implicitly allowed, which simplifies security but requires careful rule design to avoid overly permissive configurations.
- ✗
Internet Gateway
Why it's wrong here
An Internet Gateway (IGW) is a horizontally scaled, redundant VPC component that simply provides a target for internet-bound traffic and performs NAT for instances with public IPs. It does not inspect, filter, or block traffic on its own; it merely bridges the VPC to the internet. All security filtering must be enforced by security groups, Network ACLs, or an inline gateway appliance such as a NAT instance or firewall, so an IGW alone does not improve security.
- ✗
Route Tables
Why it's wrong here
Route tables determine the next hop for traffic leaving a subnet or gateway, such as directing VPC traffic to an IGW, virtual private gateway, or a peering connection. They are path-selection mechanisms, not security controls—they do not evaluate conditionality like source IP, port, or protocol, and they cannot permit or deny traffic. Even if you modify a route table to blackhole traffic, it is not a substitute for firewall filtering; it only drops traffic based on destination CIDR, not as a nuanced security policy.
- ✓
Network ACLs
Why this is correct
Network ACLs (NACLs) are stateless, subnet-level firewalls that apply to all traffic entering or leaving the subnet. They support both allow and deny rules and are evaluated in numeric order, with the first matching rule determining the outcome—so a lower-numbered deny rule for a specific port can override a higher-numbered allow rule. Because they are stateless, both inbound and outbound rules must be configured explicitly for return traffic, such as ephemeral ports, which makes them stricter but more complex than security groups.
- ✗
VPC Peering
Why it's wrong here
A VPC Peering connection is a networking link that routes traffic between two VPCs using private IP addresses, typically across accounts or regions. It does not provide any filtering, inspection, or encryption at the connection layer; it only establishes a route for traffic to flow. Any security between peered VPCs must be enforced by the security groups and Network ACLs within each VPC, or by additional appliances like a firewall in a transit VPC, so peering itself does not improve security.
Visual reference
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.