A security architect is reviewing a proposed architecture for a new e-commerce platform. The platform will handle millions of transactions daily and must be highly scalable and resilient. The architect is particularly concerned about protecting the database from direct external attacks while ensuring that application servers can access it securely. Which network segmentation strategy would be MOST effective for addressing this concern?
- APlacing the database and application servers in the same subnet with strong firewall rules.
- BUsing a dedicated VLAN for the database, isolated from all other network traffic.
- CImplementing a demilitarized zone (DMZ) with the database server.
- DDeploying the database in a private subnet, accessible only from the application servers in a public subnet.
Show answer & explanationAnswer & explanation
Correct answer: D. Deploying the database in a private subnet, accessible only from the application servers in a public subnet.
Deploying the database in a private subnet and only allowing access from application servers in a public subnet (or another private subnet) is a fundamental and highly effective network segmentation strategy. This prevents direct internet exposure of the database, significantly reducing its attack surface.
Why the other options are wrong
- A. Placing them in the same subnet increases the attack surface for the database if the application server is compromised, even with firewall rules.
- B. While using a dedicated VLAN provides logical isolation, it doesn't inherently prevent routing from other networks or direct internet exposure without additional firewalling and routing rules, and the term 'private subnet' is more precise in cloud contexts.
- C. A DMZ is typically used for publicly accessible services that need to be isolated from the internal network, not for sensitive internal databases that should never be directly exposed to the internet.
Private Subnet for Databases
A network segmentation strategy where sensitive resources like databases are placed in a private subnet (or network segment) that is not directly routable from the public internet. Access is typically restricted to specific internal resources, such as application servers.
- Prevents direct internet exposure of databases.
- Reduces the attack surface significantly.
- Forces traffic through controlled intermediaries (e.g., application servers).
- A fundamental principle in securing multi-tier applications.
Memory trick: Keep the vault in the back, behind the trusted guards.