You are correct.
The reason NAT is seen as security on home networks is that, absent a firewall, it acts as a default deny to inbound traffic.