CompTIA Cloud+ (CV0-004)Cloud ArchitectureMedium

A cloud architect is designing a multi-tier application within a Virtual Private Cloud (VPC). The application consists of a web tier, an application tier, and a database tier. The database tier must be completely isolated from direct internet access, while the web tier needs to be publicly accessible. How should the subnets be configured to meet these requirements?

  1. AWeb and application tiers in public subnets; database tier in a private subnet.
  2. BWeb tier in a public subnet; application and database tiers in private subnets.
  3. CAll tiers in public subnets.
  4. DAll tiers in private subnets.
Show answer & explanation

Correct answer: B. Web tier in a public subnet; application and database tiers in private subnets.

To meet the requirements, the web tier, needing public access, should be in a public subnet. The application and database tiers, requiring isolation from direct internet access, should be placed in private subnets. This common architecture enhances security.

Why the other options are wrong

  • A. Placing the application tier in a public subnet unnecessarily exposes it to the internet, which is generally undesirable for security best practices.
  • C. Placing all tiers in public subnets exposes the database to the internet, violating the isolation requirement.
  • D. Placing all tiers in private subnets makes the web tier inaccessible from the internet, violating the public accessibility requirement.

VPC Subnet Design (Multi-tier)

Structuring subnets within a Virtual Private Cloud to segregate application tiers based on their internet accessibility and security requirements.

  • Public subnets: internet-facing resources.
  • Private subnets: internal resources, no direct internet access.
  • Enhances security by limiting exposure of sensitive data/logic.

Memory trick: Public for show, Private for dough (data).

More Cloud Architecture questions