Subnet-level rules in a municipal VPC allow only specific ports between the web, application, and data tiers. Which control operates at that subnet scope?
Select an answer to reveal the explanation.
Short Explanation
Think of subnet NACLs as the street barriers between neighborhoods—only the ports you list get through from web to app to data. They sit at the subnet edge, not inside the SSO password policy or the object-lifecycle settings. Tight tier-to-tier port lists keep lateral movement harder.
Full Explanation
Network ACLs (NACLs) provide subnet-scoped firewall-like allow and deny rules, commonly used to restrict which ports may pass between tiers. They complement but differ from instance-level security groups and are unrelated to SSO password policies, code linting, or storage lifecycle rules. Cloud+ security controls include NACLs for subnet-level network segmentation.