In an IaaS network, which control should be configured to allow stateful, inter-subnet communication while enforcing access rules?

Enhance your skills for the CompTIA Cloud+ exam. Prepare with interactive quizzes, detailed explanations, and real exam simulations. Set the stage for your cloud certification success!

Multiple Choice

In an IaaS network, which control should be configured to allow stateful, inter-subnet communication while enforcing access rules?

Explanation:
Security groups provide a stateful firewall at the instance level, governing traffic between subnets while enforcing explicit access rules. Because they track the state of connections, once a session is allowed, the return traffic is automatically permitted without adding separate rules. This makes inter-subnet communication both controlled and seamless for legitimate flows. Host-based IPS or IDS operate inside a single host and don’t manage network paths between subnets. A network ACL sits at the subnet boundary and is typically stateless, requiring explicit rules for both directions and not inherently handling connection state, which makes it less suitable for stateful inter-subnet communication.

Security groups provide a stateful firewall at the instance level, governing traffic between subnets while enforcing explicit access rules. Because they track the state of connections, once a session is allowed, the return traffic is automatically permitted without adding separate rules. This makes inter-subnet communication both controlled and seamless for legitimate flows.

Host-based IPS or IDS operate inside a single host and don’t manage network paths between subnets. A network ACL sits at the subnet boundary and is typically stateless, requiring explicit rules for both directions and not inherently handling connection state, which makes it less suitable for stateful inter-subnet communication.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy