The Question states "AWS service or tool can be 'used' to set up a firewall" So option is C. And Network ACL is not a AWS service or tool. Correct me if i am wrong.
If the focus is solely on "setting up a firewall for a VPC subnet," Network ACLs (NACLs) are technically the mechanism you'd use. However, if the question is interpreted as "which AWS tool could manage such configurations on a broader scale," AWS Firewall Manager becomes a relevant answer.
You are right. NACL is a list of rules. It is not a tool "to setup and manage" firewall. AWS Firewall Manager is a tool to setup, configure and manage AWS WAF and AWS Shield .
The term Service is a broader classification. The key point is that Network Access Control List acts as a firewall to secure virtual private clouds (VPCs) and subnets. NACLs control and manage traffic in subnets
Network ACLs are used to control inbound and outbound traffic at the subnet level within an Amazon VPC. They provide a way to set up a firewall that operates at the network layer and are applied to all instances within a subnet.
Network ACLs are used to control inbound and outbound traffic at the subnet level within an Amazon VPC. They provide a way to set up a firewall that operates at the network layer and are applied to all instances within a subnet.
Answer D : Network Access Control Lists (NACLs)
Act as a firewall to control traffic at the subnet level, allowing or denying specific inbound or outbound traffic.
The correct answer is D. Network ACL (Access Control List).
Network ACLs act as a firewall for controlling traffic in and out of a subnet in Amazon Virtual Private Cloud (VPC). They operate at the subnet level and evaluate traffic based on rules defined for inbound and outbound traffic.
D. Network ACL (Access Control List)
Network ACLs act as a firewall for controlling traffic at the subnet level. They are stateless and operate at the subnet level, allowing or denying traffic based on rules defined for inbound and outbound traffic. Network ACLs provide an added layer of security by allowing you to specify rules that govern traffic at the network level, complementing the security groups that operate at the instance level.
Correct answer is NACL
Security Group is used for setup inbound and outbound rules in instance levels not in subnet levels. The question ask for a service or tool which serves at subnet levels. So, this answer is not correct.
NACL: Allows to setup rules at subnet levels. So this is the correct answer.
Firewall Manager: This is used for a broader perspective. It simplifies administration and maintenance tasks across multiple AWS accounts for variety of protections like WAF, Shield, Security Groups and Network Firewall etc.
C is the correct answer. The AWS Firewall Manager helps to configure a firewall and that’s what this question is asking. ”AWS Firewall Manager simplifies your AWS WAF administration and maintenance tasks across multiple accounts and resources. With AWS Firewall Manager, you set up your firewall rules just once.”
A – Security groups are essential to efficiently managing access to resources, but they are not classified as a service.
B – Web application firewall is essential to controlling traffic into and out of a network, by setting access rules and monitoring network request, but this is not the best answer.
D – Access Control Lists are used to grant or limit access to network and system resources, but they are not classified as a service.
Reference: https://AWS Firewall Manager Documentation (amazon.com)
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
pietro167
Highly Voted 1Â year, 1Â month agoreddy187
6Â months, 3Â weeks agoPenny357
Highly Voted 1Â year agonani12e434
1Â day, 1Â hour agoTaku2023
11Â months, 2Â weeks agoBShelat
1Â year agoRahul_Ghai
1Â year agoAmin_013
Most Recent 2Â weeks agoSrikanthNL
1Â month agoShaiTay
2Â months agoKilobay1
3Â months, 4Â weeks agoEvilBeaver
5Â months, 2Â weeks agoChhatwaniB
6Â months, 1Â week agogeocis
6Â months, 4Â weeks agoVal2344
8Â months agopqd
8Â months, 1Â week agochalaka
8Â months, 3Â weeks agoGallileo9
8Â months, 3Â weeks agoNilupul21
10Â months agohomodeus
10Â months agoMarysSon
10Â months, 1Â week agobd29
10Â months, 3Â weeks ago