Phase Verbs / Action Phrases
| Phrase | Meaning |
|---|---|
| regulate (access to) | control which traffic is allowed through |
| authorize (an IP range) | permit traffic from a specific address range |
| attach (to an instance) | link a security group to an EC2 instance |
| reference (a security group) | use another SG’s identity as a rule source |
| block (traffic) | prevent it from reaching the instance |
Technical Vocabulary
| Term | Definition |
|---|---|
| Security Group | A virtual firewall attached to EC2 instances; contains only allow rules |
| Inbound traffic | Network traffic coming from outside into the EC2 instance |
| Outbound traffic | Network traffic going from the EC2 instance out to the internet |
| Port | A numbered channel on a computer used for specific protocols (e.g., 80 for HTTP) |
| Protocol | Rules for how data is transmitted (e.g., TCP, UDP) |
| IP range | A range of IP addresses (e.g., 0.0.0.0/0 = all IPs; 1.2.3.4/32 = one IP) |
| CIDR | IP address range notation (e.g., 10.0.0.0/24) |
| Timeout | When a connection attempt hangs with no response — usually a security group block |
| Connection refused | Server responded but rejected the request — app error, not firewall |
| VPC | Virtual Private Cloud — network boundary within which security groups are scoped |
Key Concepts
Security Group Behavior
- Only contains allow rules (no explicit deny — unmatched traffic is denied automatically)
- Rules specify: Type, Protocol, Port, Source (IP or Security Group)
0.0.0.0/0as source = allow from anywhere- Default: all inbound blocked, all outbound allowed
Security Group Scope
- Locked to a region + VPC combination (can’t reuse across regions/VPCs)
- Lives outside the EC2 instance — blocked traffic never reaches the instance
- One security group can attach to multiple instances
- One instance can have multiple security groups
Security Group Referencing
- A rule can allow traffic from another security group (not just IPs)
- Used with load balancers: allow SG-of-LB → SG-of-EC2
- Great for decoupled services — no need to manage IP addresses
Debugging with Security Groups
| Symptom | Cause |
|---|---|
| Timeout (connection hangs) | Inbound rule is missing → security group is blocking |
| Connection refused | Security group allowed it, but app/service on EC2 has an error |
Classic Ports You Must Know
| Port | Protocol | Used For |
|---|---|---|
| 22 | SSH | Secure Shell — log into Linux instances |
| 22 | SFTP | Secure File Transfer (uses SSH) |
| 21 | FTP | File Transfer Protocol (unsecured) |
| 80 | HTTP | Unencrypted web traffic |
| 443 | HTTPS | Encrypted web traffic |
| 3389 | RDP | Remote Desktop Protocol — log into Windows instances |
Exam Tips
- Security groups = allow rules only (no deny rules)
- Default = inbound blocked, outbound open
- Timeout → security group issue; connection refused → app issue
- One SG can be shared across multiple instances
- Port 22 = SSH (Linux) | Port 3389 = RDP (Windows) — know both
- Security groups can reference other security groups (very useful for load balancers)