A SysOps administrator needs to configure a highly available and scalable network architecture for a web application. The application will be hosted on Amazon EC2 instances in a private subnet, and users must access it via a public IP address. Security requirements dictate that only HTTP and HTTPS traffic should reach the application instances. Which combination of AWS services should be used?
- ANAT Gateway, Direct Connect, Gateway Load Balancer, VPC Peering
- BVirtual Private Gateway, Transit Gateway, Network Load Balancer (NLB), NACL
- CInternet Gateway, VPC Endpoint, Classic Load Balancer (CLB), Route Table
- DInternet Gateway, NAT Gateway, Application Load Balancer (ALB), Security Group
Show answer & explanationAnswer & explanation
Correct answer: D. Internet Gateway, NAT Gateway, Application Load Balancer (ALB), Security Group
An Internet Gateway provides internet connectivity for the VPC. An Application Load Balancer (ALB) distributes HTTP/HTTPS traffic to EC2 instances in private subnets and can be configured with listeners for these protocols. A Security Group acts as a virtual firewall for the instances, allowing only specified traffic (HTTP/HTTPS). If instances are in private subnets, they don't need a NAT Gateway for inbound traffic from the internet through an ALB, but the ALB itself would be in a public subnet. The question implies public access to the application, and the ALB provides this while routing to private instances.
Why the other options are wrong
- A. NAT Gateway is for private instances to initiate outbound internet connections. Direct Connect is for dedicated network connection to AWS. Gateway Load Balancer is for third-party virtual appliances. VPC Peering connects two VPCs.
- B. Virtual Private Gateway and Transit Gateway are for VPN/inter-VPC connectivity. NLB operates at Layer 4. NACLs are subnet-level firewalls, less granular than security groups for instance-specific rules.
- C. VPC Endpoints are for private access to AWS services, not public internet access to an application. CLB is an older generation load balancer, less feature-rich for HTTP/HTTPS than ALB.
Public-facing Web Architecture
A common AWS architecture for hosting web applications that are accessible from the internet, ensuring high availability, scalability, and security.
- Uses Internet Gateway for internet connectivity.
- Employs Load Balancers (ALB for HTTP/HTTPS) for traffic distribution.
- Security Groups protect instances at the network interface level.
Memory trick: Internet Gateway opens the door, ALB directs traffic, Security Group guards the instances.