AWS Network Firewall is a managed, stateful network firewall for your VPC. It gives you fine-grained control over traffic — intrusion prevention, domain filtering, and custom rules — at the VPC level.

Where it fits

Security groups and NACLs are basic instance/subnet controls; Network Firewall adds deep, stateful inspection across the whole VPC (block malicious domains, filter by protocol, IPS/IDS). The tell is “advanced/centralized network traffic filtering and intrusion prevention” beyond what security groups offer.

Test yourself

Practice question

A company needs advanced, stateful traffic inspection and intrusion prevention across an entire VPC, beyond what security groups and NACLs provide. Which service?

  1. A larger security group
  2. AWS Network Firewall
  3. AWS WAF
  4. A NAT gateway
👉 Click to reveal the answer & explanation

Correct answer: B. AWS Network Firewall provides managed, stateful, VPC-wide traffic inspection and intrusion prevention. Security groups (A) are basic instance-level filters; WAF (C) filters web (layer-7) requests, not general VPC traffic; NAT (D) is for outbound internet access.

Related topics

Security groups vs NACLs · AWS WAF · Amazon VPC

CloudExamPro Premium

Ready to pass the AWS Solutions Architect Associate (SAA-C03)?

Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.

  • ✓  6 full-length practice exams
  • ✓  A detailed explanation for every single question
  • ✓  Realistic, scenario-based questions — not memory dumps
  • ✓  Lifetime access, kept current for 2026

Get the SAA-C03 Practice Exams →or try 25 free questions first

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access