Security groups present in a VPC provides you the liberty to specify both inbound and outbound network traffic. All the traffic which is not explicitly allowed to or from an instance is automatically denied. The other side of security groups are that all the traffic entering and exiting the subnet can be allowed or declined using Network ACL.