AWS Network Firewall is a managed, stateful network firewall for your VPC. It gives you fine-grained control over traffic — intrusion prevention, domain filtering, and custom rules — at the VPC level.
Where it fits
Security groups and NACLs are basic instance/subnet controls; Network Firewall adds deep, stateful inspection across the whole VPC (block malicious domains, filter by protocol, IPS/IDS). The tell is “advanced/centralized network traffic filtering and intrusion prevention” beyond what security groups offer.
Test yourself
A company needs advanced, stateful traffic inspection and intrusion prevention across an entire VPC, beyond what security groups and NACLs provide. Which service?
- A larger security group
- AWS Network Firewall
- AWS WAF
- A NAT gateway
👉 Click to reveal the answer & explanation
Correct answer: B. AWS Network Firewall provides managed, stateful, VPC-wide traffic inspection and intrusion prevention. Security groups (A) are basic instance-level filters; WAF (C) filters web (layer-7) requests, not general VPC traffic; NAT (D) is for outbound internet access.
Related topics
Security groups vs NACLs · AWS WAF · Amazon VPC
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first