A cloud security analyst observes that a specific EC2 instance is receiving inbound traffic on port 22, despite the associated network ACL explicitly denying all inbound TCP traffic on that port. The instance's security group allows port 22. Which architectural behavior explains why the traffic was permitted?
Select an answer to reveal the explanation.
Short Explanation
Think of it like building security: you have a door lock (security group) on the room and a hallway gate (NACL) for the whole floor. The door lock is stateful, so it remembers who's already inside and lets them back in. The hallway gate is stateless, checking every ticket individually without remembering the context. If your door lock says 'yes' to an established connection, it lets traffic through even if the hallway gate's rule set is rigid, because they operate at different layers and states.
Full Explanation
Security groups function as stateful, instance-level firewalls that maintain a state table for active connections. When an inbound connection is established and allowed by the security group, return traffic for that session is automatically permitted, regardless of stateless rules elsewhere. Network ACLs, conversely, are stateless controls applied at the subnet boundary. They evaluate each packet independently without regard to connection state. In this scenario, the security group's stateful nature allows the traffic flow to persist because it recognizes the connection context, effectively bypassing the strict stateless deny logic of the ACL for that specific session. A distractor suggesting ACLs are evaluated after security groups is incorrect because the evaluation order does not change the fundamental stateful vs. stateless behavior; the security group's state tracking is the decisive factor. Another distractor claiming security groups are stateless contradicts their core definition. Finally, asserting that ACLs only apply to outbound traffic is factually wrong, as ACLs govern both inbound and outbound rules at the subnet level. Exam caveat: Always distinguish between stateful (security groups) and stateless (NACLs) when troubleshooting connectivity in IaaS environments. Operational check: Verify the security group's inbound rules for the specific port and confirm the NACL's inbound rules allow the ephemeral return ports if necessary for stateless evaluation.