1 Answers
Yes it is :).
In reality, the best way to isolate backend instances from Internet is removing public IP from them.
But I assume that, in the context of this lesson, the instructor wants us to practice and understand various aspects of VPC firewall rules, so he sticks with whatever the default configuration is (ephemeral IP) ^^.
I think one of the requirement is also to block pinging front end VMs