advanced·20 min·Kostenpflichtig

Web Tier Bypasses App Tier

Security review finds the web servers can talk directly to the database — they shouldn't be able to

Szenario

The customer-facing application is built in three tiers, each on its own subnet: a web tier that talks to the public Internet, an application tier that the web tier talks to for business logic, and a database tier that only the application tier is supposed to reach. A routine security review found that web-tier servers can connect directly to the database tier, completely bypassing the application tier — a serious defense-in-depth violation, since a compromised web server should never be able to touch the database directly.

Lernziele

  • acl
  • nftables
  • least privilege

Topologie und Konfiguration

Diese Umgebung enthält 4 Geräte (3 Hosts, 1 Router). Sie konfigurieren und beheben Fehler bei den oben aufgeführten Networking-Fähigkeiten.

Lehrplanthemen

subnetica© 2026 · Lernen, üben, behalten.
Über unsFAQDatenschutzerklärungNutzungsbedingungenBarrierefreiheitcontact@subneti.ca
CCNA ist eine eingetragene Marke von Cisco Systems, Inc. CompTIA Network+ und CompTIA Security+ sind eingetragene Marken der CompTIA, Inc. Subnetica ist eine unabhängige Lernplattform und steht in keiner Verbindung zu Cisco Systems, Inc. oder CompTIA, Inc. und wird von diesen weder unterstützt noch gesponsert.