Both are firewalls in your VPC, and the architect exam loves making you pick. The trick is two things: what level each works at, and whether it’s stateful.

The two differences that matter

A security group wraps an instance and is stateful — allow traffic out and the reply is automatically allowed back. A network ACL wraps a subnet and is stateless — you allow both directions yourself. Security groups only allow; NACLs can also explicitly deny.

Test yourself

Practice question

You need to block one specific malicious IP address from reaching an entire subnet. Which tool?

  1. A security group deny rule
  2. A network ACL deny rule
  3. An IAM policy
  4. A route table entry
👉 Click to reveal the answer & explanation

Correct answer: B. Network ACLs support explicit deny rules and operate at the subnet level. Security groups (A) only allow (no deny) and work per instance; IAM (C) governs API permissions, not network traffic; route tables (D) direct traffic, they don’t block IPs.

Related topics

Amazon VPC · AWS IAM · Elastic Load Balancing

CloudExamPro Premium

Ready to pass the AWS Solutions Architect Associate (SAA-C03)?

Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.

  • ✓  6 full-length practice exams
  • ✓  A detailed explanation for every single question
  • ✓  Realistic, scenario-based questions — not memory dumps
  • ✓  Lifetime access, kept current for 2026

Get the SAA-C03 Practice Exams →or try 25 free questions first

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access