Question 1 of 30
A company is planning to set up a multi-tier application architecture in AWS using Amazon VPC. They want to ensure that their web servers can communicate with the application servers while restricting direct access to the database servers from the internet. The company has decided to use two subnets: a public subnet for the web servers and a private subnet for the application and database servers. Which of the following configurations would best achieve this architecture while adhering to AWS best practices?
Create a public subnet with an Internet Gateway attached and a private subnet with a NAT Gateway for outbound internet access. Configure security groups to allow traffic from the public subnet to the private subnet on the application server port, and restrict all inbound traffic to the database server.
Create a public subnet with an Internet Gateway attached and a private subnet without a NAT Gateway. Allow all traffic from the public subnet to the private subnet and allow inbound traffic to the database server from the internet.
Create a public subnet with a NAT Gateway and a private subnet with an Internet Gateway attached. Allow all traffic from the public subnet to the private subnet and allow inbound traffic to the database server from the public subnet.
Create a private subnet with an Internet Gateway and a public subnet with a NAT Gateway. Allow all traffic from the private subnet to the public subnet and allow inbound traffic to the database server from the internet.

Preparing for Amazon SOA-C02 AWS Certified SysOps Administrator – Associate (SOA-C02)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free