CCSP Cloud Platform and Infrastructure Security Practice Question
Which TWO of the following are characteristics of security groups compared to network ACLs in a cloud VPC? (Select two.)
⚠ Common exam trap
A common mix-up: candidates confuse the stateful nature of security groups with the stateless nature of network ACLs, and forgetting that security groups only support allow rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Stateful – return traffic is automatically allowed
Option B is correct because security groups are stateful: when an inbound or outbound connection is permitted, the return traffic for that established flow is automatically allowed without needing a separate rule, unlike network ACLs which are stateless. Option E is correct because security groups only support allow rules; there is no way to create an explicit deny rule in a security group, whereas network ACLs support both allow and deny rules. Options A, C, and D describe network ACLs rather than security groups: network ACLs operate at the subnet level (A), are stateless and evaluate each packet independently (C), and support both allow and deny rules (D), so they do not belong as characteristics of security groups.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Operate at the subnet level
Why it's wrong here
Security groups attach to elastic network interfaces of individual resources, not to subnets; subnet-level filtering is the network ACL's role. It is tempting because subnet-wide rules appear to simplify management, and that is exactly the correct choice when you need uniform filtering applied to every instance within a tier.
- ✓
Stateful – return traffic is automatically allowed
Why this is correct
Security groups track connection state, so response traffic for an established flow is permitted automatically without a matching inbound rule. Network ACLs are stateless and require explicit rules for both directions, which is the axis of difference.
- ✗
Stateless – each packet is evaluated independently
Why it's wrong here
Security groups are stateful: return traffic is automatically permitted, so packets are not evaluated independently. Statelessness describes network ACLs, which assess each packet against inbound and outbound rules separately. That contrast is what makes this tempting, but it inverts the actual axis of difference between the two constructs.
- ✗
Support both allow and deny rules
Why it's wrong here
Security groups are stateful and allow-only; deny rules are expressed by omission, whereas network ACLs carry explicit numbered allow and deny entries. It is tempting because deny rules feel like the stronger control, and they are the correct mechanism when you must block a specific CIDR range at the subnet boundary.
- ✓
Only allow rules can be specified
Why this is correct
Security groups are stateful and permit only allow rules; every rule is permissive, with no deny syntax available. This satisfies the stem's constraint of distinguishing security group behaviour from network ACLs, which uniquely support both allow and deny rules evaluated in numbered order.
Visual reference
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.