CCSP Cloud Platform and Infrastructure Security Practice Question
In a cloud VPC, what is the difference between security groups and network ACLs (NACLs)?
⚠ Common exam trap
CCSP often tests the stateful/stateless and allow-only/allow-deny distinction, and candidates frequently reverse the two (e.g., thinking SGs support deny or that NACLs are stateful), which is exactly the trap this question sets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security groups are stateful and support allow rules only; NACLs are stateless and support allow and deny rules
Security groups are stateful—return traffic for an allowed inbound connection is automatically permitted—and they support only allow rules, with an implicit deny for anything not explicitly allowed. NACLs are stateless—each direction must be explicitly allowed, including ephemeral return ports—and they support both allow and deny rules, evaluated in numbered order. This stateful/stateless and allow-only/allow-deny distinction is the core difference.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security groups are stateful and support allow rules only; NACLs are stateless and support allow and deny rules
Why this is correct
Security groups operate at the instance level, are stateful, and permit allow rules only. NACLs operate at the subnet level, are stateless, and support both allow and deny rules, so return traffic must be explicitly permitted in each direction.
- ✗
Security groups support allow and deny rules; NACLs support only allow
Why it's wrong here
Security groups are allow-only; NACLs carry both allow and deny rules, so this reverses the actual model. It is tempting because NACLs' numbered deny rules are memorable, but the stem asks which statement correctly distinguishes the two mechanisms.
- ✗
Security groups are stateless and NACLs are stateful
Why it's wrong here
Security groups are stateful, tracking established connections, while NACLs are stateless and evaluate each packet independently, so this inverts the pair. It is tempting because both enforce filtering, but the stateful/stateless axis is exactly what the question tests.
- ✗
Security groups and NACLs are both stateless
Why it's wrong here
Security groups are stateful, automatically permitting return traffic for established flows; only NACLs are stateless. It is tempting because NACLs do evaluate packets individually, but claiming both are stateless ignores connection tracking in security groups.
Visual reference
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.