An extra 30% off every course until Sunday, October 11.Choose your certification →

Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

3.4.2.1. Network Security Components (Security Groups, Network ACLs, Network Firewall, WAF, Shield)

3.4.2.1. Network Security Components (Security Groups, Network ACLs, WAF)

Network security operates at multiple layers — each catching different types of threats.

Security Groups (instance-level firewall):
  • Stateful: Return traffic automatically allowed
  • Allow rules only: No explicit deny rules
  • Applied to: ENIs (network interfaces on EC2, RDS, Lambda VPC, etc.)
  • Sources can be other security groups: reference the ALB's security group (sg-…) instead of its IP addresses; the rule follows every ENI in that group even as the ALB's IPs change
Network ACLs (subnet-level firewall):
  • Stateless: Must allow both inbound AND outbound explicitly
  • Allow AND deny rules: Rules evaluated by number (lowest first)
  • Applied to: Subnets
FeatureSecurity GroupNetwork ACL
ScopeInstance (ENI)Subnet
StateStatefulStateless
RulesAllow onlyAllow and Deny
EvaluationAll rules evaluatedFirst match wins
DefaultDeny all inboundAllow all
AWS WAF (web application firewall):
  • Protects CloudFront, ALB, API Gateway, AppSync
  • Rules: SQL injection, XSS, rate limiting, geo-blocking, IP reputation
  • Managed rule groups (AWS, marketplace vendors) provide pre-built protection
  • Rate-based rules can be narrowed with a scope-down statement (e.g., URI path starts with /login) and custom aggregation keys, so a sensitive endpoint gets a much lower threshold than the site-wide limit
{
  "Name": "RateLimitRule",
  "Priority": 1,
  "Action": {"Block": {}},
  "Statement": {
    "RateBasedStatement": {
      "Limit": 2000,
      "AggregateKeyType": "IP"
    }
  }
}

Exam Trap: Security group changes take effect immediately — but existing connections using the old rules remain active until they close. If you remove an allow rule for port 443, existing HTTPS connections continue until the client or server closes them. To immediately terminate connections, you must also terminate the associated instances or close the connections at the application level.

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder•20 professional certifications