A company is designing a new multi-tier web application on AWS. The application uses an Auto Scaling group of EC2 instances for the web tier and an Amazon RDS for PostgreSQL DB instance for the database. To improve security, the company wants to ensure that the web tier instances can connect to the database only through a specific port and that the database is not accessible from the internet. Which steps should the company take? (Choose THREE.)
Trap 1: Launch the database instance in a public subnet.
A public subnet exposes the RDS instance to internet routing, contradicting the requirement that the database be unreachable from the internet. Public subnets are tempting because they suit internet-facing load balancers and bastion hosts, but RDS belongs in private subnets reachable only from the web tier's security group.
Trap 2: Store database credentials in AWS Systems Manager Parameter Store.
Parameter Store secures credential storage and rotation, but it neither restricts database access to a specific port nor removes internet reachability, so it fails the stated security objectives. It is tempting because it is a genuine best practise for secrets management, and would be correct if the question asked how to avoid hard-coded credentials.
- A
Launch the database instance in a public subnet.
Why it fails: A public subnet exposes the RDS instance to internet routing, contradicting the requirement that the database be unreachable from the internet. Public subnets are tempting because they suit internet-facing load balancers and bastion hosts, but RDS belongs in private subnets reachable only from the web tier's security group.
- B
Configure the database security group to allow inbound traffic on port 5432 from the web tier security group.
Referencing the web tier's security group as the source restricts inbound database traffic to those instances only, on port 5432. This enforces the requirement that connections arrive solely through the PostgreSQL port from the web tier, rather than any broader CIDR range.
- C
Store database credentials in AWS Systems Manager Parameter Store.
Why it fails: Parameter Store secures credential storage and rotation, but it neither restricts database access to a specific port nor removes internet reachability, so it fails the stated security objectives. It is tempting because it is a genuine best practise for secrets management, and would be correct if the question asked how to avoid hard-coded credentials.
- D
Launch the web tier instances in a private subnet.
Private subnets have no route to an internet gateway, so web tier instances cannot receive inbound connections from the internet. This supports the requirement that the database remain unreachable externally while instances still reach it internally within the VPC.
- E
Set the 'Publicly accessible' option of the RDS instance to 'No'.
Setting Publicly accessible to No removes the RDS instance's public DNS endpoint and public IP, so it can only be reached from within the VPC. This directly satisfies the requirement that the database not be accessible from the internet.