A Virtual Private Cloud (VPC) is your own isolated section of the AWS cloud. You define its IP address range (CIDR block), create subnets, configure route tables, and control network access with security groups and NACLs.
A virtual firewall for EC2 instances and other resources that controls inbound and outbound traffic at the instance level using allow rules.
A stateless firewall at the subnet level that controls inbound and outbound traffic using numbered allow and deny rules.
Dividing a network into isolated segments (subnets, VPCs) to limit lateral movement and contain the blast radius of a security breach.
A private connection between your VPC and an AWS service that keeps traffic within the AWS network, eliminating the need for internet access.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.