Ch. 15 · AWS

AWS Security Groups Versus Network ACLs

AWS Security Groups Versus Network ACLs. Learn the reasoning, a practical example, common mistakes and an interview exercise.

~2 min readbeginnerupdated Oct 3, 2026

Security groups and network ACLs apply at different boundaries and have different stateful behavior. Evaluate both directions of the connection.

Before you start

You should understand regions, identity permissions and the responsibilities of the AWS service being discussed. Sketch request flow and failure boundaries before choosing configuration. Work through these scenarios as designs; provisioning real resources can introduce charges and requires an account-specific permissions and capacity plan.

The practical goal is to reason through this situation: A permitted inbound request can still fail due to subnet-level return-path restrictions. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.

Step-by-step walkthrough

Step 1: Locate each boundary

Security groups and network ACLs apply at different scopes.

Step 2: Account for return traffic

Stateful and stateless behavior changes which directions need explicit permission.

Step 3: Test the complete connection

Initial ingress success does not establish that replies can return.

Worked scenario

A permitted inbound request can still fail due to subnet-level return-path restrictions.

A subnet ACL permits inbound traffic to the application port but blocks required return-path traffic. A permissive security group does not override that subnet denial. Diagnose source, destination, ports and direction at each layer, including relevant ephemeral traffic, rather than copying identical rules between controls.

Common mistake

Treating their rule semantics as identical causes incomplete troubleshooting.

Verify the behavior

Verify connection establishment and replies with the actual network path.

Interview exercise

Choose a restrictive network policy.

Answer and reasoning

State the required source, destination and return traffic, then verify the actual controls along the path.

Continue learning

Compare the scenario with the AWS interview questions and test your understanding with the AWS MCQs. For terminology and implementation details, consult the reference material.

More in AWS

read ✓AWS · hard

AWS Secrets Manager and Rotation

Store secrets centrally, rotate credentials automatically with a two-user pattern, and fetch them at runtime.

~2 min readread →
esc