AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium

A financial services company is migrating a critical, multi-tier application to AWS. The application consists of EC2 instances running web servers, application servers, and a database server. Due to strict compliance regulations, all communication between the application tiers must be encrypted in transit, and the network traffic between the EC2 instances must be isolated from the public internet. Furthermore, access to the database tier should only be permitted from the application servers. Which architecture best meets these security requirements?

  1. ADeploy all EC2 instances in separate private subnets within a single VPC, using security groups to restrict traffic between tiers and a VPC endpoint for database access.
  2. BDeploy web servers in a public subnet, and application and database servers in separate private subnets, using security groups and network ACLs for traffic control.
  3. CDeploy all EC2 instances in a single public subnet with security groups to control traffic.
  4. DDeploy all EC2 instances in a single private subnet with a NAT Gateway for outbound internet access and security groups.
Show answer & explanation

Correct answer: B. Deploy web servers in a public subnet, and application and database servers in separate private subnets, using security groups and network ACLs for traffic control.

This architecture provides the necessary segregation and control. Web servers, being public-facing, belong in a public subnet. Application and database servers, which are internal, must be in private subnets to isolate them from the internet. Security groups are stateful and ideal for controlling inter-tier communication (e.g., app servers to database), and Network ACLs provide an additional, stateless layer of defense at the subnet level.

Why the other options are wrong

  • A. Deploying all instances in separate private subnets is good, but without a public subnet for web servers, it makes the application inaccessible from the internet unless a public-facing load balancer is explicitly mentioned and configured, which is not the case here. VPC endpoints are for services, not direct EC2 instance access between tiers for general application communication.
  • C. Deploying all instances in a public subnet exposes internal tiers to the internet, violating isolation requirements.
  • D. While placing all instances in a private subnet isolates them, it doesn't allow for public-facing web servers and unnecessarily complicates inbound access for web servers if they were to be public-facing. It also doesn't separate application and database tiers adequately for stricter isolation.

Multi-Tier VPC Architecture

A common AWS architecture pattern that segregates application components into different network tiers (subnets) based on their public accessibility and security requirements.

  • Public subnets for internet-facing resources (e.g., load balancers, web servers).
  • Private subnets for internal resources (e.g., application servers, databases).
  • Security groups and Network ACLs control traffic flow between tiers and to/from the internet.

Memory trick: Public for Front, Private for Back, NACLs Block, SGs Track.

More Design Secure Architectures questions