読み込み中
Q1Not attemptedView question

Security groups versus network ACLs by scope and behavior

Security group = per-instance, stateful, allow-rules only. Per-subnet, stateless, and both allow/deny is the NACL. Distinguish them by layer and characteristics.