A project manager is deploying a new web application to a cloud environment. The application requires high availability and automatic scaling based on traffic. Which IT infrastructure component should the project manager use to meet these requirements?
Trap 1: Firewall
A firewall filters and inspects traffic at network boundaries; it neither hosts application instances nor distributes load or scales capacity with demand. It is tempting because every cloud web deployment includes one, and it would be the right answer if the requirement were controlling inbound and outbound traffic rather than high availability and automatic scaling.
Trap 2: DNS server
A DNS server resolves names to addresses; it provides neither horizontal scaling nor health-based failover. It is tempting because DNS can front multiple endpoints, and would be correct if the requirement were routing clients to a regional endpoint or performing simple round-robin distribution.
Trap 3: VPN concentrator
A VPN concentrator terminates encrypted tunnels for remote-access or site-to-site connectivity; it provides no compute capacity, load distribution or autoscaling. It is tempting because it is a genuine cloud-edge appliance, and would be correct if the requirement were secure remote user access into the environment rather than hosting a highly available, elastically scaling web tier.
- A
Load balancer
A load balancer distributes incoming traffic across multiple backend instances and performs health checks, removing failed nodes from rotation. Combined with an auto-scaling group it delivers the high availability and traffic-based scaling the web application requires, which a single server cannot provide.
- B
Firewall
Why it fails: A firewall filters and inspects traffic at network boundaries; it neither hosts application instances nor distributes load or scales capacity with demand. It is tempting because every cloud web deployment includes one, and it would be the right answer if the requirement were controlling inbound and outbound traffic rather than high availability and automatic scaling.
- C
DNS server
Why it fails: A DNS server resolves names to addresses; it provides neither horizontal scaling nor health-based failover. It is tempting because DNS can front multiple endpoints, and would be correct if the requirement were routing clients to a regional endpoint or performing simple round-robin distribution.
- D
VPN concentrator
Why it fails: A VPN concentrator terminates encrypted tunnels for remote-access or site-to-site connectivity; it provides no compute capacity, load distribution or autoscaling. It is tempting because it is a genuine cloud-edge appliance, and would be correct if the requirement were secure remote user access into the environment rather than hosting a highly available, elastically scaling web tier.