How do public and private subnets differ in an AWS Virtual Private Cloud (VPC)? What types of resources should be placed in each subnet, and how do they impact security, internet access, and application architecture? Which best practices do you follow when designing subnet layouts in AWS?