Answers: B and E
Option A is incorrect. The entry point to the Application is the ELB. It`s best to have only the ELB within the Public Subnet and have the Application & Database in the Private subnet. This way, a user can access the application through the ELB to provide High Availability & failover.
Option B is CORRECT. This is the best possible configuration that can be defined for maximum Security, High Availability & Failover.
Option C is incorrect. This configuration will be least Secure since users will be able to access all the Application, Database & ELB within the Public Subnet. Also, single points of failure may occur due to a lack of proper services structuring within the respective layers.
Option D is incorrect since the Application should be placed within the Private Subnet that should not route the Internet Gateway. Instead, it should have a route to the NAT gateway for accessing the Internet in an Egress manner.
Option E is CORRECT. A NAT gateway allows resources hosted within the Private Subnet to access the Internet for operations like OS updates or DB patch updates. Since the ELB is the only resource within a Public Subnet, it should ideally contain a NAT Gateway that will allow the Application or Database to access the Internet.
Diagram:
The figure below shows a typical configuration of an ELB, EC2 instance, RDS, NAT Gateway, Bastion host & route table. The NAT Gateway & Bastion Host is contained within the Public Subnet along with the ELB, while the EC2 instance & RDS is contained within a Private Subnet.
References:
https://youtu.be/tD9vDv0uyI8
https://docs.aws.amazon.com/vpc/latest/userguide/what-is-amazon-vpc.html