What is the difference between a security group and a network ACL?
Assesses fundamental understanding of AWS conventions, runtime behavior, and memory/performance considerations.
Hiring managers look for precision, avoidance of ambiguous jargon, and ability to explain trade-offs under real production conditions.
Both control traffic in a VPC, but at different layers.
- Security groups are stateful and attached to ENIs or instances. Return traffic is automatically allowed. Rules are allow-only and evaluated as a whole.
- Network ACLs are stateless and attached to subnets. You must allow both inbound and outbound traffic, including ephemeral ports. They support allow and deny rules and are evaluated in numbered order, lowest first.
aws ec2 describe-security-groups --group-ids sg-0abc123
aws ec2 describe-network-acls --filters Name=association.subnet-id,Values=subnet-123
By default, security groups deny all inbound and allow all outbound; the default NACL allows everything. A typical design uses security groups for fine-grained instance rules and NACLs as a coarse subnet-level guardrail.
Candidate Response Strategy & Interview Tips
- Start with a concise one-sentence summary: Deliver a direct, confident answer first before expanding into nuances.
- Demonstrate real-world trade-offs: Discuss where this approach excels and when you would avoid it in production systems.
- Discuss complexity & edge cases: Proactively explain time/space complexity or boundary conditions (null values, scale limits).
- Prepare for interviewer follow-ups: Technical hiring panels frequently probe deeper into concurrency, backward compatibility, or alternative libraries.