Phase 7 · Identity & Security
TopicsSecurity Groups vs Network ACLs
Part of the Cloud Computing Roadmap.
Summary
Security groups are stateful and apply at the instance level; network ACLs are stateless and apply at the subnet level — using both together provides defense in depth for network access control.
How to Learn This
- 1Configure both a security group and a network ACL for the same resource and compare their rules.
- 2Learn why 'stateful' means a security group automatically allows return traffic, but an ACL doesn't.
- 3Practice reasoning about which layer to use for a specific access control requirement.
More topics in Identity & Security
Stuck on this topic? Ask an Insider
Get 1:1 guidance from people who've walked this exact path — free on the InsideEdge app.