A security engineer is designing a network architecture for a three-tier web application. The web tier must be accessible from the internet, but the application and database tiers must not. Which VPC configuration should be used?
This standard three-tier design places only the web tier in public subnets with a route to an internet gateway so it can serve external users. The app and database tiers are in private subnets with no internet gateway route, preventing direct inbound connections from the internet; the app tier receives traffic from the web tier through an internal load balancer or security group rules, and the database is isolated to app-tier-only access. This minimizes the attack surface and is the correct pattern for a public-facing web application.
Why this answer
It places the web tier in public subnets with an internet gateway for direct internet access, while the application and database tiers reside in private subnets with no direct internet route. This ensures that only the web tier is exposed, and the app and database tiers can only be reached through the web tier via internal routing, aligning with the principle of least privilege for a three-tier architecture.
Exam trap
The trap here is that candidates often confuse security groups with subnet routing, assuming that restrictive security groups alone can prevent internet access even when the subnet is public, but the route table's default route to an internet gateway still allows inbound traffic from the internet.
How to eliminate wrong answers
Option A is wrong because placing the app tier in a public subnet exposes it to the internet, violating the requirement that only the web tier be accessible from the internet. Option C is wrong because using a VPN for external access would require all traffic to go through the VPN, which is unnecessary and adds complexity; the web tier is meant to be publicly accessible without VPN. Option D is wrong because placing all tiers in public subnets, even with security groups, still exposes the app and database tiers to potential internet-facing risks, as security groups alone do not prevent direct internet access from the subnet's route table.