Security groups and network ACLs apply at different boundaries and have different stateful behavior. Evaluate both directions of the connection.
Before you start
You should understand regions, identity permissions and the responsibilities of the AWS service being discussed. Sketch request flow and failure boundaries before choosing configuration. Work through these scenarios as designs; provisioning real resources can introduce charges and requires an account-specific permissions and capacity plan.
The practical goal is to reason through this situation: A permitted inbound request can still fail due to subnet-level return-path restrictions. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.
Step-by-step walkthrough
Step 1: Locate each boundary
Security groups and network ACLs apply at different scopes.
Step 2: Account for return traffic
Stateful and stateless behavior changes which directions need explicit permission.
Step 3: Test the complete connection
Initial ingress success does not establish that replies can return.
Worked scenario
A permitted inbound request can still fail due to subnet-level return-path restrictions.
A subnet ACL permits inbound traffic to the application port but blocks required return-path traffic. A permissive security group does not override that subnet denial. Diagnose source, destination, ports and direction at each layer, including relevant ephemeral traffic, rather than copying identical rules between controls.
Common mistake
Treating their rule semantics as identical causes incomplete troubleshooting.
Verify the behavior
Verify connection establishment and replies with the actual network path.
Interview exercise
Choose a restrictive network policy.
Answer and reasoning
State the required source, destination and return traffic, then verify the actual controls along the path.
Continue learning
Compare the scenario with the AWS interview questions and test your understanding with the AWS MCQs. For terminology and implementation details, consult the reference material.