AWS VPC, Subnets, and Security Groups
What common mistakes do candidates make around AWS VPC, Subnets, and Security Groups, and how do you avoid them?
Answers use simple, clear English.
Quick interview answer
Common mistakes: 0.0.0.0/0 on SSH SG; databases in public subnets. Best practices: Least privilege SG; VPC endpoints for S3/ECR; flow logs.
Detailed answer
Common mistakes: 0.0.0.0/0 on SSH SG; databases in public subnets. Best practices: Least privilege SG; VPC endpoints for S3/ECR; flow logs. Core: VPC CIDR, public/private subnets, IGW/NAT, route tables. Security groups stateful allow-lists; NACLs stateless. Private workloads without public IPs. Real-time example: ALB in public subnets; ECS tasks in private; NAT for egress. Pros: Strong network isolation primitives. Cons: Misconfigured routes cause outages. Common mistakes: 0.0.0.0/0 on SSH SG; databases in public subnets. Best practices: Least privilege SG; VPC endpoints for S3/ECR; flow logs. Audience level: Fresher.
Full explanation
VPC CIDR, public/private subnets, IGW/NAT, route tables. Security groups stateful allow-lists; NACLs stateless. Private workloads without public IPs.
Real example & use case
ALB in public subnets; ECS tasks in private; NAT for egress.
Pros & cons
Pros: Strong network isolation primitives. Cons: Misconfigured routes cause outages.
Common mistakes
0.0.0.0/0 on SSH SG; databases in public subnets.
Best practices
Least privilege SG; VPC endpoints for S3/ECR; flow logs.
Follow-up questions
- How would you test AWS VPC, Subnets, and Security Groups?
- What metrics prove AWS VPC, Subnets, and Security Groups is healthy in prod?
- How does AWS VPC, Subnets, and Security Groups change at 10× traffic?