advanced·20 min·De pago

Web Tier Bypasses App Tier

Security review finds the web servers can talk directly to the database — they shouldn't be able to

Escenario

The customer-facing application is built in three tiers, each on its own subnet: a web tier that talks to the public Internet, an application tier that the web tier talks to for business logic, and a database tier that only the application tier is supposed to reach. A routine security review found that web-tier servers can connect directly to the database tier, completely bypassing the application tier — a serious defense-in-depth violation, since a compromised web server should never be able to touch the database directly.

Objetivos de aprendizaje

  • acl
  • nftables
  • least privilege

Topología y configuración

Este entorno contiene 4 dispositivos (3 Hosts, 1 Router). Configuras y solucionas problemas de las habilidades de redes listadas arriba.

Temas del plan de estudios

subnetica© 2026 · Aprende, practica, retén.
Acerca dePreguntas frecuentesPolítica de privacidadTérminos y uso aceptableAccesibilidadcontact@subneti.ca
CCNA es una marca registrada de Cisco Systems, Inc. CompTIA Network+ y CompTIA Security+ son marcas registradas de CompTIA, Inc. Subnetica es una plataforma de aprendizaje independiente y no está afiliada, avalada ni patrocinada por Cisco Systems, Inc. ni CompTIA, Inc.