AWS Security and Cost Management Concepts
Dev Bhosale
Principal Data & Cloud Architect



| Feature | NACL (Network Access Control List) | Security Groups |
|---|---|---|
| Scope | Subnet-level | Instance-level |
| Statefulness | Stateless | Stateful |
| Default Rules | Denies all unless allowed | Allows outbound |
| Best for | Broad network layer control | Granular instance |




AWS Security and Cost Management Concepts