Security groups act as firewalls to protect incoming traffic to cloud servers, with security group rules set on demand. End-to-end security protection includes DDoS mitigation, WAF (Web Application Firewall), and bastion hosts.