Q78Design Secure Architectures
A company has built a multi-tier application for its ecommerce website. The website uses: - an Application Load Balancer in the public subnets, - a web tier in the public subnets, and - a MySQL cluster hosted on Amazon EC2 instances in the private subnets. The MySQL database must retrieve product catalog and pricing information that is hosted on the internet by a third-party provider. A solutions architect must design a strategy that maximizes security without increasing operational overhead. What should the solutions architect do to meet these requirements?
← → navigate · a answer
Community votes
Discussion · 6
B 4
Deploy a NAT gateway in the public subnets. Modify the private subnet route table to direct all internet-bound traffic to the NAT gateway
B 4
Correct Answer: B
B 3
NAT Gateway is safe
B 3
A: Probably an old question so this option is here but NAT instance is overhead
C: Not secure as IG opens up a lot of things
D: VPG connects to a service
B: NG is managed solution. Secure by config
B 3
Deploy a NAT gateway in the public subnets. Modify the private subnet route table to direct all internet-bound traffic to the NAT gateway.
2
B is correct