Correct Answers: A and B
The AWS Documentation mentions the following
A security group acts as a virtual firewall for your instance to control inbound and outbound traffic. When you launch an instance in a VPC, you can assign up to five security groups to the instance.
A network access control list (ACL) is an optional layer of security for your VPC that acts as a firewall for controlling traffic in and out of one or more subnets. You might set up network ACLs with rules similar to your security groups in order to add an additional layer of security to your VPC.Option C is incorrect since this is used to decide on the DNS servers for the VPC
Option D is incorrect since this is used for routing traffic in the VPC
For more information on VPC security groups and NACL’s, please visit the below URL
https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_SecurityGroups.html
https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_ACLs.html