Both are firewalls in your VPC, and the architect exam loves making you pick. The trick is two things: what level each works at, and whether it’s stateful.
The two differences that matter
A security group wraps an instance and is stateful — allow traffic out and the reply is automatically allowed back. A network ACL wraps a subnet and is stateless — you allow both directions yourself. Security groups only allow; NACLs can also explicitly deny.
Test yourself
You need to block one specific malicious IP address from reaching an entire subnet. Which tool?
- A security group deny rule
- A network ACL deny rule
- An IAM policy
- A route table entry
👉 Click to reveal the answer & explanation
Correct answer: B. Network ACLs support explicit deny rules and operate at the subnet level. Security groups (A) only allow (no deny) and work per instance; IAM (C) governs API permissions, not network traffic; route tables (D) direct traffic, they don’t block IPs.
Related topics
Amazon VPC · AWS IAM · Elastic Load Balancing
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first