AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationEasy

A developer needs to deploy a new web application that requires a highly available and scalable database. The database should only be accessible from application servers within specific private subnets and should not be exposed to the public internet. Which AWS service and configuration would best meet these requirements?

  1. AUse Amazon RDS Multi-AZ deployment in private subnets, configured with appropriate security groups.
  2. BSet up a database on an Amazon EC2 instance in a private subnet, accessible via a NAT Gateway.
  3. CProvision an Amazon DynamoDB table and expose it via a VPC Gateway Endpoint in a public subnet.
  4. DDeploy an Amazon EC2 instance with a database installed, placed in a public subnet with a security group.
Show answer & explanation

Correct answer: A. Use Amazon RDS Multi-AZ deployment in private subnets, configured with appropriate security groups.

Amazon RDS Multi-AZ deployment provides high availability and automatic failover for relational databases. Placing it in private subnets ensures it's not publicly accessible, and security groups can restrict access to only the application servers, meeting all requirements efficiently.

Why the other options are wrong

  • B. While an EC2 database in a private subnet is private, a NAT Gateway is for outbound internet access, not for inbound connections to the database, and it lacks built-in high availability.
  • C. DynamoDB is a NoSQL database, which might not fit 'database' generically, and exposing a VPC Gateway Endpoint in a public subnet is unnecessary and could be misinterpreted for public access to the database itself.
  • D. Placing a database in a public subnet is a security risk and does not provide built-in high availability.

Amazon RDS Multi-AZ

A deployment option for Amazon Relational Database Service (RDS) that automatically provisions and maintains a synchronous standby replica in a different Availability Zone.

  • Provides high availability and data durability.
  • Automatic failover to the standby replica.
  • Can be deployed in private subnets for enhanced security.

Memory trick: RDS Multi-AZ: Redundant, Reliable, Restricted.

More Network Implementation questions