Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

In a cloud VPC, what is the difference between security groups and network ACLs (NACLs)?

⚠ Common exam trap

CCSP often tests the stateful/stateless and allow-only/allow-deny distinction, and candidates frequently reverse the two (e.g., thinking SGs support deny or that NACLs are stateful), which is exactly the trap this question sets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security groups are stateful and support allow rules only; NACLs are stateless and support allow and deny rules

Security groups are stateful—return traffic for an allowed inbound connection is automatically permitted—and they support only allow rules, with an implicit deny for anything not explicitly allowed. NACLs are stateless—each direction must be explicitly allowed, including ephemeral return ports—and they support both allow and deny rules, evaluated in numbered order. This stateful/stateless and allow-only/allow-deny distinction is the core difference.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Security groups are stateful and support allow rules only; NACLs are stateless and support allow and deny rules

    Why this is correct

    Security groups operate at the instance level, are stateful, and permit allow rules only. NACLs operate at the subnet level, are stateless, and support both allow and deny rules, so return traffic must be explicitly permitted in each direction.

  • ✗

    Security groups support allow and deny rules; NACLs support only allow

    Why it's wrong here

    Security groups are allow-only; NACLs carry both allow and deny rules, so this reverses the actual model. It is tempting because NACLs' numbered deny rules are memorable, but the stem asks which statement correctly distinguishes the two mechanisms.

  • ✗

    Security groups are stateless and NACLs are stateful

    Why it's wrong here

    Security groups are stateful, tracking established connections, while NACLs are stateless and evaluate each packet independently, so this inverts the pair. It is tempting because both enforce filtering, but the stateful/stateless axis is exactly what the question tests.

  • ✗

    Security groups and NACLs are both stateless

    Why it's wrong here

    Security groups are stateful, automatically permitting return traffic for established flows; only NACLs are stateless. It is tempting because NACLs do evaluate packets individually, but claiming both are stateless ignores connection tracking in security groups.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.