A company is hosting a public-facing web application on AWS using Amazon EC2 instances behind an Application Load Balancer (ALB). The EC2 instances store sensitive customer data, and the security team mandates that these instances must not be directly accessible from the internet. They should only receive traffic from the ALB. Which network design principle, combined with security groups, would best achieve this requirement?
- ADeploying the ALB in a public subnet and the EC2 instances in private subnets.
- BDeploying the ALB and EC2 instances in private subnets with a NAT Gateway.
- CDeploying the ALB in a private subnet and the EC2 instances in public subnets.
- DDeploying the ALB and EC2 instances in public subnets.
Show answer & explanationAnswer & explanation
Correct answer: A. Deploying the ALB in a public subnet and the EC2 instances in private subnets.
To protect EC2 instances from direct internet access while allowing them to receive traffic from an ALB, the ALB should be in a public subnet to receive internet traffic, and the EC2 instances should be in private subnets. Security groups can then be configured on the EC2 instances to only allow inbound traffic from the ALB's security group, ensuring isolation.
Why the other options are wrong
- B. Deploying the ALB in a private subnet would prevent it from receiving public internet traffic, making the web application inaccessible from the internet.
- C. Deploying EC2 instances in public subnets violates the security mandate, and an ALB in a private subnet would not be public-facing.
- D. Deploying EC2 instances in public subnets makes them directly accessible from the internet, violating the security mandate.
ALB & EC2 Private Subnet
A common secure architecture where an Application Load Balancer (ALB) is deployed in public subnets to face the internet, while backend EC2 instances are deployed in private subnets to protect them from direct internet access.
- ALB in public subnets for internet-facing access.
- EC2 instances in private subnets for isolation.
- Security groups control traffic flow between ALB and EC2 instances.
Memory trick: ALB Public Front, EC2 Private Back, Keep Internet Track.