← AWS Security Specialty: evidence-based security
03 / 8 · 35 MIN

Networking and administrative access

Evaluate rules, return paths, and audit limits.

Concept and mechanism

A network control’s effect depends on its scope. Security groups attached to the same interface aggregate Allow rules; a narrower group does not cancel an opening in another group. There is no rule selecting the most restrictive group. Permission at this control also does not guarantee the whole path, which may depend on routes, NACLs, and application behavior. NACLs evaluate rules numerically and stop at the first match. A more specific network in a later rule does not win because of specificity, unlike prefix-routing intuition. Analyze inbound and outbound paths because a NACL is stateless.

Guided application

In HTTPS diagnosis, allowing inbound 443 does not guarantee return traffic to the client ephemeral port. Identify each direction and the blocking control before broadening rules. Exceptions also exist: a NACL does not block AmazonProvidedDNS queries; consider the appropriate DNS control, such as Route 53 Resolver DNS Firewall, for that objective. For administration, Session Manager can reduce inbound-port exposure and centralize authorization. However, content recording is unavailable for SSH or port-forwarding sessions. CloudTrail can record API calls, which is not equivalent to commands inside the tunnel. Choose an administrative path meeting the actual evidence requirement.

IN PRACTICE

Rule 100 allows a /16 and rule 200 denies a contained /24. A matching packet is allowed by the first rule.

Common pitfalls

Restrictive group as Deny; more specific prefix as NACL priority; API logging as recorded shell.

Related topics: WAF and GenAI application protection · Federation and delegation across entities

Take this idea with you

Check semantics, order, and scope of each control on the complete path.

Create account

Reference: Network ACLs · SCS-C03