AWS Certified SysOps Administrator – AssociateNetworking and Content DeliveryMedium

A SysOps administrator needs to configure a highly available and scalable network architecture for a web application. The application will be hosted on Amazon EC2 instances in a private subnet, and users must access it via a public IP address. Security requirements dictate that only HTTP and HTTPS traffic should reach the application instances. Which combination of AWS services should be used?

  1. ANAT Gateway, Direct Connect, Gateway Load Balancer, VPC Peering
  2. BVirtual Private Gateway, Transit Gateway, Network Load Balancer (NLB), NACL
  3. CInternet Gateway, VPC Endpoint, Classic Load Balancer (CLB), Route Table
  4. DInternet Gateway, NAT Gateway, Application Load Balancer (ALB), Security Group
Show answer & explanation

Correct answer: D. Internet Gateway, NAT Gateway, Application Load Balancer (ALB), Security Group

An Internet Gateway provides internet connectivity for the VPC. An Application Load Balancer (ALB) distributes HTTP/HTTPS traffic to EC2 instances in private subnets and can be configured with listeners for these protocols. A Security Group acts as a virtual firewall for the instances, allowing only specified traffic (HTTP/HTTPS). If instances are in private subnets, they don't need a NAT Gateway for inbound traffic from the internet through an ALB, but the ALB itself would be in a public subnet. The question implies public access to the application, and the ALB provides this while routing to private instances.

Why the other options are wrong

  • A. NAT Gateway is for private instances to initiate outbound internet connections. Direct Connect is for dedicated network connection to AWS. Gateway Load Balancer is for third-party virtual appliances. VPC Peering connects two VPCs.
  • B. Virtual Private Gateway and Transit Gateway are for VPN/inter-VPC connectivity. NLB operates at Layer 4. NACLs are subnet-level firewalls, less granular than security groups for instance-specific rules.
  • C. VPC Endpoints are for private access to AWS services, not public internet access to an application. CLB is an older generation load balancer, less feature-rich for HTTP/HTTPS than ALB.

Public-facing Web Architecture

A common AWS architecture for hosting web applications that are accessible from the internet, ensuring high availability, scalability, and security.

  • Uses Internet Gateway for internet connectivity.
  • Employs Load Balancers (ALB for HTTP/HTTPS) for traffic distribution.
  • Security Groups protect instances at the network interface level.

Memory trick: Internet Gateway opens the door, ALB directs traffic, Security Group guards the instances.

More Networking and Content Delivery questions