Labs · Cyber Security
Lab: Whiteboard Practice: Draw and Explain a Secure 3-Tier Web App on AWS in 10 Minutes
Course: Cyber Security · Chapter 47: Interview Questions Asked in MNC Interviews
Chapter 47 covers questions asked in MNC interviews; this lab practises the common "design a secure web app" whiteboard round.
Chala mitrano! In many MNC interviews you get a marker and a question: "Design a secure web application." They are not checking drawing skills. They want to see layers: who can talk to whom, where the data lives, how you would notice an attack and how you would recover. Today we practise that in 10 minutes. Chala, marker ghya!
चला मित्रांनो! अनेक MNC interviews मध्ये तुमच्या हातात marker आणि प्रश्न येतो: "Secure web application design करा." ते drawing skills check करत नाहीत. त्यांना layers बघायचे असतात: कोण कोणाशी बोलू शकतो, data कुठे राहतो, attack कसा लक्षात येईल आणि recover कसं कराल. आज आपण 10 मिनिटांत याची practice करणार. चला, marker घ्या!
चलो दोस्तों! कई MNC interviews में आपको marker और सवाल मिलता है: "एक secure web application design करो।" वो drawing skills नहीं देखते। उन्हें layers देखनी हैं: कौन किससे बात कर सकता है, data कहाँ रहता है, attack का पता कैसे चलेगा और recover कैसे करोगे। आज हम 10 मिनट में इसकी practice करेंगे। चलो, marker उठाओ!
Suppose we are…
Suppose we are in the second round for a cloud security role at Deloitte. The interviewer says: "Our client is building an online pharmacy like PharmEasy on AWS. Draw how you would host it securely: web, app and database. You have 10 minutes." We practise drawing and explaining it, then score ourselves.
Goal of this lab
By the end you will be able to draw and explain, in 10 minutes:
- Three tiers: an Application Load Balancer, app servers and an RDS database, in public and private subnets across two Availability Zones.
- Chained security groups: internet → ALB on 443, ALB → app, app → database on 3306.
- Identity, encryption, logging, backups, and what you would monitor.
What you need (all free)
- Paper and pen, a whiteboard, or diagrams.net in your browser. A timer. About 40 minutes including two attempts.
Safety and ethics
Use only general, public architecture patterns. Do not draw or describe a current or former employer's real internal network, IP ranges or security gaps in an interview.
Steps
- Set a 10-minute timer. Draw a big box labelled VPC 10.0.0.0/16 with two columns, AZ-a and AZ-b.
- Draw three rows of subnets in each AZ: Public (
10.0.1.0/24,10.0.2.0/24), App private (10.0.11.0/24,10.0.12.0/24), DB private (10.0.21.0/24,10.0.22.0/24). - Above the VPC draw Users → Route 53 (DNS) → AWS WAF → Application Load Balancer (in the public subnets, with an ACM certificate for HTTPS).
- Put EC2 app servers (or an Auto Scaling group) in the app subnets, and RDS MySQL Multi-AZ in the DB subnets.
-
Write the security group chain next to the arrows:
sg-alb: inbound 443 from0.0.0.0/0(and 80 only to redirect to 443).sg-app: inbound 80 from sg-alb only.sg-db: inbound 3306 from sg-app only. No public access on RDS (Lab 15).
What you should see: no arrow from the internet reaches the app or database directly.
-
Add outbound internet for updates: a NAT gateway in a public subnet for the app subnets (mention it has an hourly cost), or VPC endpoints for S3.
- Add the side boxes: S3 for images and prescriptions (Block Public Access, presigned URLs, Lab 14), IAM role on EC2 instead of access keys (Lab 16), Secrets Manager for the DB password, KMS encryption for RDS and S3.
- Add detect and recover: CloudTrail (Lab 30), CloudWatch alarms and ALB access logs, GuardDuty, RDS automated backups and snapshots, AMI or launch templates to rebuild app servers.
- Admin access: no SSH from the internet. Use AWS Systems Manager Session Manager (or a bastion limited to your IP, Lab 4).
- When the timer stops, explain the drawing aloud in 3 minutes, from the user to the database: "A user's request goes through…". Record it if you like (Lab 46).
-
Score yourself (1 point each, 8 points):
# Did I show… 1 Public vs private subnets and two AZs 2 HTTPS at the ALB with a certificate 3 Security groups chained by SG reference, DB not public 4 WAF or rate limiting at the front (Lab 40) 5 IAM role and secrets manager, no keys in code 6 Encryption at rest (RDS, S3) 7 Logging and monitoring (CloudTrail, CloudWatch, GuardDuty) 8 Backups and how to rebuild What you should see: a score out of 8. Note the missing points.
-
Wait at least an hour, then redraw from memory in 10 minutes and score again.
Ravindra Bagale's Tip
Talk while you draw, and start with the user. Interviewers love it when you mention trade-offs: "Multi-AZ RDS doubles the database cost, so for a small start-up I would…". That shows real thinking, not memorised boxes. Kharcha pan vichaar kara!
Ravindra Bagale's Tip – मराठी
Draw करताना बोलत राहा, आणि user पासून सुरुवात करा. तुम्ही trade-offs सांगितले की interviewers ना आवडतं: "Multi-AZ RDS मुळे database चा खर्च दुप्पट होतो, म्हणून छोट्या start-up साठी मी…". यातून खरा विचार दिसतो, पाठ केलेले boxes नाही. खर्चाचा पण विचार करा!
Ravindra Bagale's Tip – हिंदी
Draw करते हुए बोलते रहो, और user से शुरू करो। Trade-offs बताओ तो interviewers को अच्छा लगता है: "Multi-AZ RDS से database का खर्च दोगुना होता है, तो छोटे start-up के लिए मैं…"। इससे असली सोच दिखती है, रटे हुए boxes नहीं। खर्च का भी सोचो!
Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
| Database in a public subnet "for easy access" | Interviewer stops you there | DB private, SG from app only |
| Security groups using IP ranges everywhere | Hard to manage, easy to over-open | Reference SGs (sg-app from sg-alb) |
| Forgetting monitoring and backups | Design looks like it cannot detect or recover | Add CloudTrail, CloudWatch, GuardDuty, backups |
| SSH open to 0.0.0.0/0 for admins | Common finding in real audits | Session Manager or bastion on your IP |
| Drawing silently for 10 minutes | Interviewer cannot follow your thinking | Explain as you draw |
Self-check checklist
0 of 5 done
Try-at-home challenge
The interviewer asks: "The pharmacy stores prescription images. What changes?" Add it to your drawing in 2 minutes.
Check your answer
Store images in a private S3 bucket with Block Public Access, SSE-KMS encryption and versioning; the app gives users short-lived presigned URLs (Lab 14); the app's IAM role can access only that bucket prefix; S3 access logging or CloudTrail data events record who read what; and a lifecycle rule handles retention as required by health-data rules. Mention that prescriptions are sensitive personal data under India's DPDP Act.
Samjla ka? Layers from user to database, chained security groups, plus detect and recover. Aata pudhe jaauya: Chapter 48 maps everything to the CEH exam.