Service Comparison

Security Group vs Network ACL

Security groups protect resources. NACLs filter subnet traffic.

What They Have in Common

Each option can solve part of the scenario. The exam expects you to choose the one that satisfies the stated constraints with the right operational burden, security boundary, availability model, and cost behavior.

Key Differences

OptionPrimary modelBest useSecurityAvailabilityOperations and cost
Security groupStatefulAllow rules onlyENI/resource levelApplies to reachable resource targetsLow ops; changes are attached to resources
Network ACLStatelessAllow and deny rulesSubnet levelApplies across subnet traffic pathsHigher rule-order burden; useful for broad subnet filtering

Typical Exam Clues

Practice After Studying

Return to the certification guide that includes this comparison and launch domain training from there.

Sources and Review Metadata