Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A cloud operations team is configuring a virtual private cloud (VPC) and needs to control both inbound and outbound traffic at the subnet level. The team wants to ensure that any traffic leaving the subnet is explicitly allowed, and that responses to inbound requests are automatically permitted. Which VPC component should the team configure?

⚠ Common exam trap

The trap here is assuming that security groups can provide subnet-level control because they are stateful, when in fact they operate at the instance level and cannot enforce explicit outbound rules at the subnet boundary.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network ACLs, because they are stateless and can enforce explicit allow/deny rules for both inbound and outbound traffic at the subnet boundary.

Network ACLs are stateless and operate at the subnet level, requiring explicit rules for both inbound and outbound traffic. This makes them the correct choice for controlling traffic at the subnet boundary with explicit outbound allowances. Security groups are stateful and instance-level, route tables direct traffic without filtering, and flow logs only record metadata without enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security groups, because they are stateful and evaluate all traffic at the instance level.

    Why it's wrong here

    Security groups are stateful and operate at the instance level, not the subnet level. They automatically allow return traffic for permitted inbound requests, but they do not provide subnet-level control. The requirement is for subnet-level traffic filtering with explicit outbound rules, which security groups do not fulfill because they are attached to elastic network interfaces, not subnets.

  • ✓

    Network ACLs, because they are stateless and can enforce explicit allow/deny rules for both inbound and outbound traffic at the subnet boundary.

    Why this is correct

    Network ACLs are stateless and operate at the subnet level. They require explicit rules for both inbound and outbound traffic, and return traffic must be allowed by an outbound rule. This matches the requirement to control traffic at the subnet level with explicit outbound allowances. They are the correct component for subnet-level traffic filtering in a VPC.

  • ✗

    VPC flow logs, because they capture metadata about traffic and can be used to enforce outbound restrictions.

    Why it's wrong here

    VPC flow logs capture metadata about IP traffic for monitoring and analysis, but they do not enforce any traffic restrictions. They are a logging and auditing tool, not a security control. Relying on flow logs to control outbound traffic would be ineffective because they cannot block or allow packets; they only record what has already happened.

  • ✗

    Route tables, because they determine which subnet traffic is directed to and can block unauthorized destinations.

    Why it's wrong here

    Route tables control where traffic is routed, not whether it is allowed or denied. They do not inspect traffic or enforce security policies based on ports or protocols. While they can direct traffic to a firewall appliance, they do not themselves provide the explicit allow/deny rules required for subnet-level traffic control, so they are not the correct component here.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.