Security Group Exam frequency ★★★★★

Security Group

Security Group

Security GroupENIStatefulSAA-C03
Last organized

A stateful, allow-only virtual firewall attached to an ENI or supported resource, central to resource-level least privilege in AWS.

In one sentence

A security group is a stateful, allow-only virtual firewall attached to an ENI or supported resource.

Core purpose

  • Control traffic entering and leaving an ENI.
  • Define rules by protocol, port, source or destination CIDR, or another security group.
  • Combine the allow rules of every security group attached to the same ENI.
  • Express least-privilege relationships without explicit deny rules.

What does stateful mean?

When an inbound request is allowed, its related return traffic is automatically allowed without a matching outbound rule, and vice versa.

“Stateful” means tracking an allowed connection; it does not mean that all unrelated reverse traffic bypasses the rules.

Default behavior

  • A new security group has no inbound allow rules.
  • It normally allows all outbound traffic by default.
  • The default security group also has an inbound rule allowing members of the same default group to communicate.
  • Defaults can be changed, so troubleshooting should always use the actual configuration.

Three-tier pattern

  • ALB SG: allow internet traffic to port 443.
  • Application SG: allow the ALB security group to the application port.
  • RDS SG: allow the application security group to the database port.

Referencing security groups expresses “who may reach whom” more clearly than fixed IP addresses.

Exam focus

  • Resource or ENI level.
  • Stateful behavior.
  • Allow rules only.
  • Rules from multiple security groups are combined.
  • Use security group references for ALB → application → database access.
  • Troubleshoot together with routes, NACLs, host firewalls, and application listeners.

Common misconceptions

  • Security groups cannot contain explicit deny rules.
  • They are not attached directly to an entire subnet.
  • Stateful does not mean that every outbound restriction is ignored.
  • An open security group alone does not guarantee connectivity.

Security Group vs Network ACL

DimensionSecurity GroupNetwork ACL
ScopeENI or resourceSubnet boundary
StateStatefulStateless
RulesAllow onlyAllow and deny
EvaluationAll allow rules combinedLowest-numbered first match

Key takeaway

A security group is a resource guard: it issues passes and remembers established connections.