ANS-C01 Network Design Practice Question
A company is designing a network for a three-tier web application in AWS. The web tier must be accessible from the internet, but the application and database tiers must be private. The company wants to use a single AWS Region and ensure high availability across multiple Availability Zones. What is the MOST cost-effective network design that meets these requirements?
⚠ Common exam trap
AWS often tests the misconception that a single NAT Gateway is more cost-effective than multiple, but the trap is that cross-AZ data transfer costs from using a single NAT Gateway in a multi-AZ setup can exceed the cost of deploying one NAT Gateway per AZ, making the per-AZ design more cost-effective overall.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place web servers in public subnets across three AZs. Place application and database servers in private subnets across three AZs. Use a NAT Gateway in each AZ for outbound traffic.
It places web servers in public subnets across three Availability Zones (AZs) for internet-facing access and high availability, while application and database servers reside in private subnets across three AZs for isolation. A NAT Gateway in each AZ provides cost-effective outbound internet connectivity for private instances without exposing them to inbound traffic, and using one NAT Gateway per AZ avoids cross-AZ data transfer charges, which would increase costs if a single NAT Gateway were shared across AZs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Place web servers in public subnets across three AZs. Place application and database servers in private subnets across three AZs. Use a NAT Gateway in each AZ for outbound traffic.
Why this is correct
Highly available and cost-effective managed service.
- ✗
Place web servers in public subnets across three AZs. Place application and database servers in private subnets across three AZs. Use NAT instances in each AZ behind an Auto Scaling group.
Why it's wrong here
NAT instances require management overhead and are less cost-effective.
- ✗
Place web servers in public subnets and application/database servers in private subnets in one AZ. Use a single NAT Gateway in the public subnet for outbound traffic.
Why it's wrong here
Single AZ is not highly available; single NAT Gateway is a SPOF.
- ✗
Place all tiers in public subnets and use security groups to restrict inbound traffic to the web tier only.
Why it's wrong here
Public subnets expose instances to the internet; not secure.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
4 more ways this is tested on ANS-C01
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A startup wants to design a cost-effective network for a new application. They expect low traffic initially but need to handle sudden spikes. They plan to use Amazon EC2 instances behind an Application Load Balancer (ALB) in a single VPC. The application must be highly available within the region. The network engineer has proposed using two public subnets in two Availability Zones for the ALB, and two private subnets for the EC2 instances. The EC2 instances need to access the internet for updates. What is the MOST cost-effective and highly available design?
easy- A.Use a single NAT instance in one public subnet
- ✓ B.Use a NAT gateway in each public subnet (one per AZ)
- C.Use a NAT instance in each public subnet (one per AZ)
- D.Use a single NAT gateway in one public subnet
Why B: Using a NAT gateway in each Availability Zone provides high availability because each AZ has its own NAT gateway, eliminating a single point of failure. NAT gateways are managed by AWS, reducing operational overhead compared to NAT instances. Option A is wrong because a single NAT instance is a single point of failure. Option C is wrong because while NAT instances per AZ provide high availability, they require manual management and are less cost-effective than using managed NAT gateways. Option D is wrong because a single NAT gateway is a single point of failure.
Variation 2. A company is designing a network for a three-tier web application in a single VPC. The web tier must be accessible from the internet, but the application and database tiers must not have direct internet access. The application servers need to make outbound calls to a third-party API. Which architecture meets these requirements?
easy- A.Web servers in public subnets, application and database servers in private subnets with an internet gateway for outbound traffic.
- B.All servers in public subnets with security groups restricting access.
- ✓ C.Web servers in public subnets with an Application Load Balancer, application servers in private subnets with a NAT gateway, and database servers in private subnets.
- D.All servers in private subnets and a VPN connection to the internet.
Why C: It places web servers in public subnets with an Application Load Balancer for inbound internet traffic, while application and database servers reside in private subnets without direct internet access. A NAT gateway in a public subnet enables the application servers to initiate outbound connections to a third-party API, with return traffic automatically routed back, meeting the requirement for outbound-only internet access.
Variation 3. An application running on EC2 instances in a private subnet needs to download patches from the internet. The VPC has an internet gateway and public subnets. Which resource should be used to provide outbound internet access to the instances?
easy- A.VPC gateway endpoint for S3
- ✓ B.NAT gateway in a public subnet
- C.AWS Site-to-Site VPN connection
- D.Internet gateway in the private subnet
Why B: A NAT gateway in a public subnet provides outbound-only internet access to instances in private subnets by translating their private IP addresses to the NAT gateway's Elastic IP address. This allows the EC2 instances to download patches from the internet while preventing any unsolicited inbound connections from the internet, which is the standard design for secure outbound internet access in a VPC.
Variation 4. A solutions architect is designing a VPC with public and private subnets in two Availability Zones. The private subnets require outbound internet access for software updates, but inbound internet access must be blocked. Which solution meets these requirements?
easy- A.Attach an internet gateway to the VPC and add a default route to the internet gateway in the private subnet route tables.
- ✓ B.Deploy a NAT Gateway in a public subnet and add a default route to the NAT Gateway in the private subnet route tables.
- C.Launch an EC2 instance in a public subnet with a proxy software and route private subnet traffic through it.
- D.Create a VPC endpoint for Amazon S3 and add a route to the endpoint in the private subnet route tables.
Why B: A NAT Gateway, deployed in a public subnet with an Elastic IP and a route to an Internet Gateway, enables outbound traffic from private subnets to the internet while blocking unsolicited inbound connections. The private subnet route table directs default traffic (0.0.0.0/0) to the NAT Gateway, which performs source network address translation (SNAT) on outbound packets, ensuring responses return to the NAT Gateway without exposing private instances directly.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.