Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

Which TWO of the following are characteristics of security groups compared to network ACLs in a cloud VPC? (Select two.)

⚠ Common exam trap

A common mix-up: candidates confuse the stateful nature of security groups with the stateless nature of network ACLs, and forgetting that security groups only support allow rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Stateful – return traffic is automatically allowed

Option B is correct because security groups are stateful: when an inbound or outbound connection is permitted, the return traffic for that established flow is automatically allowed without needing a separate rule, unlike network ACLs which are stateless. Option E is correct because security groups only support allow rules; there is no way to create an explicit deny rule in a security group, whereas network ACLs support both allow and deny rules. Options A, C, and D describe network ACLs rather than security groups: network ACLs operate at the subnet level (A), are stateless and evaluate each packet independently (C), and support both allow and deny rules (D), so they do not belong as characteristics of security groups.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Operate at the subnet level

    Why it's wrong here

    Security groups attach to elastic network interfaces of individual resources, not to subnets; subnet-level filtering is the network ACL's role. It is tempting because subnet-wide rules appear to simplify management, and that is exactly the correct choice when you need uniform filtering applied to every instance within a tier.

  • ✓

    Stateful – return traffic is automatically allowed

    Why this is correct

    Security groups track connection state, so response traffic for an established flow is permitted automatically without a matching inbound rule. Network ACLs are stateless and require explicit rules for both directions, which is the axis of difference.

  • ✗

    Stateless – each packet is evaluated independently

    Why it's wrong here

    Security groups are stateful: return traffic is automatically permitted, so packets are not evaluated independently. Statelessness describes network ACLs, which assess each packet against inbound and outbound rules separately. That contrast is what makes this tempting, but it inverts the actual axis of difference between the two constructs.

  • ✗

    Support both allow and deny rules

    Why it's wrong here

    Security groups are stateful and allow-only; deny rules are expressed by omission, whereas network ACLs carry explicit numbered allow and deny entries. It is tempting because deny rules feel like the stronger control, and they are the correct mechanism when you must block a specific CIDR range at the subnet boundary.

  • ✓

    Only allow rules can be specified

    Why this is correct

    Security groups are stateful and permit only allow rules; every rule is permissive, with no deny syntax available. This satisfies the stem's constraint of distinguishing security group behaviour from network ACLs, which uniquely support both allow and deny rules evaluated in numbered order.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.