Public and Private Network Segments
Subnets with direct internet access through Internet Gateway.
Subnets without direct internet access, using NAT for outbound traffic.
Deploy subnets across multiple AZs for fault tolerance
Spread resources across AZs for better performance