AWS Certified Cloud Practitioner (CLF-C02)Cloud Technology and ServicesMedium

A company is designing a VPC architecture for a three-tier web application. Web servers must be reachable from the internet, while the database servers must never be directly accessible from the internet. How should the company design the subnets to meet this requirement?

  1. APlace both the web servers and database servers in the same public subnet
  2. BPlace both the web servers and database servers in a private subnet with no internet gateway
  3. CPlace the web servers in a public subnet and the database servers in a private subnet
  4. DPlace the web servers in a private subnet and the database servers in a public subnet
Show answer & explanation

Correct answer: C. Place the web servers in a public subnet and the database servers in a private subnet

Public subnets have a route to an internet gateway and should host resources like web servers that need direct internet access, while private subnets lack a direct internet gateway route and are appropriate for backend resources like databases that should stay isolated from the public internet.

Why the other options are wrong

  • A. Putting the database in a public subnet exposes it directly to the internet, violating the requirement.
  • B. If web servers are private with no internet gateway, external users cannot reach the application at all.
  • D. Reversing the design would prevent users from reaching the web servers and expose the database.

Public vs Private Subnets

Public subnets route traffic to an internet gateway, allowing direct internet access; private subnets do not have this direct route, isolating resources from the internet.

  • Public subnets host internet-facing resources like web servers or load balancers
  • Private subnets host backend resources like databases
  • NAT gateways allow private subnet outbound internet access without inbound exposure

Memory trick: Public greets the world, private guards the data.

More Cloud Technology and Services questions