What it is: A stateful virtual firewall for instances (and some other ENIs).
What it’s for:
Key ideas:
Stateful: if inbound is allowed, the return traffic is automatically allowed.
Rules are allow-only (no explicit deny rules in SG).
You can reference other security groups as source/destination.
Exam cues:
Hard words:
*stateful* /ˈsteɪtfəl/: có trạng thái (tự cho phép traffic phản hồi)
*firewall* /ˈfaɪərˌwɔːl/: tường lửa
*protocol* /ˈproʊtəkɔːl/: giao thức