AWS Certified SysOps Administrator SOA-C01 – Question439

A custom network ACL that you create ____ until you add rules, and is not associated with a sub-net until you explicitly associate it with one.

A.
blocks only inbound traffic by default
B. allows outbound traffic by default
C. allows all inbound and outbound traffic by default
D. blocks all inbound and outbound traffic by default

Correct Answer: D

Explanation:

Explanation: You can create a custom network ACL for your VPC. By default, a network ACL that you create blocks all inbound and outbound traffic until you add rules, and is not associated with a subnet until you explicitly associate it with one. The default NACL that is created with your VPC allows all inbound and outbound traffic by de-fault. Reference:
http://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_ACLs.html…