Courseiva

SOA-C02 Networking and Content Delivery Practice Question

Which TWO AWS services can be used to improve the security of a VPC? (Choose TWO.)

⚠ Common exam trap

It's easy for candidates to confuse routing components (Internet Gateway, Route Tables, VPC Peering) with security components, assuming any VPC construct that controls traffic flow also provides security filtering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security Groups

Security Groups (A) act as a virtual firewall for instances, controlling inbound and outbound traffic at the instance level based on allow rules only. Network ACLs (D) provide a stateless firewall layer at the subnet level, supporting both allow and deny rules, and are evaluated in numeric order. Together, they offer defense-in-depth for VPC traffic filtering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Security Groups

    Why this is correct

    Security Groups are stateful virtual firewalls that operate at the ENI/instance level within a VPC. They evaluate all inbound and outbound traffic against a set of allow rules only—there is no explicit deny rule—and return traffic is automatically permitted regardless of the outbound rule configuration. For example, if you allow inbound HTTP from 0.0.0.0/0, the corresponding outbound response traffic is implicitly allowed, which simplifies security but requires careful rule design to avoid overly permissive configurations.

  • ✗

    Internet Gateway

    Why it's wrong here

    An Internet Gateway (IGW) is a horizontally scaled, redundant VPC component that simply provides a target for internet-bound traffic and performs NAT for instances with public IPs. It does not inspect, filter, or block traffic on its own; it merely bridges the VPC to the internet. All security filtering must be enforced by security groups, Network ACLs, or an inline gateway appliance such as a NAT instance or firewall, so an IGW alone does not improve security.

  • ✗

    Route Tables

    Why it's wrong here

    Route tables determine the next hop for traffic leaving a subnet or gateway, such as directing VPC traffic to an IGW, virtual private gateway, or a peering connection. They are path-selection mechanisms, not security controls—they do not evaluate conditionality like source IP, port, or protocol, and they cannot permit or deny traffic. Even if you modify a route table to blackhole traffic, it is not a substitute for firewall filtering; it only drops traffic based on destination CIDR, not as a nuanced security policy.

  • ✓

    Network ACLs

    Why this is correct

    Network ACLs (NACLs) are stateless, subnet-level firewalls that apply to all traffic entering or leaving the subnet. They support both allow and deny rules and are evaluated in numeric order, with the first matching rule determining the outcome—so a lower-numbered deny rule for a specific port can override a higher-numbered allow rule. Because they are stateless, both inbound and outbound rules must be configured explicitly for return traffic, such as ephemeral ports, which makes them stricter but more complex than security groups.

  • ✗

    VPC Peering

    Why it's wrong here

    A VPC Peering connection is a networking link that routes traffic between two VPCs using private IP addresses, typically across accounts or regions. It does not provide any filtering, inspection, or encryption at the connection layer; it only establishes a route for traffic to flow. Any security between peered VPCs must be enforced by the security groups and Network ACLs within each VPC, or by additional appliances like a firewall in a transit VPC, so peering itself does not improve security.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.