Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company has 200 AWS accounts in AWS Organizations and a shared services VPC in a central networking account. Each workload account needs to reach an on-premises data center over a single AWS Direct Connect connection that terminates in the networking account. The company wants to minimize cost and avoid managing individual VPC peering connections. Which solution should a solutions architect recommend?

⚠ Common exam trap

The trap here is assuming VPC peering is transitive or that PrivateLink provides general on-premises routing, when only a transit gateway shared through AWS Resource Access Manager centralizes connectivity at scale.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a transit gateway in the networking account, attach the Direct Connect gateway and all workload VPCs to it, and share the transit gateway using AWS Resource Access Manager.

A transit gateway in the networking account acts as a regional hub that connects the Direct Connect gateway and all workload VPCs. AWS Resource Access Manager shares the transit gateway with other accounts in the organization, so workload accounts attach their VPCs without creating peering meshes or per-account VPNs. This scales cleanly and reduces cost and operational overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy an AWS Site-to-Site VPN over the Direct Connect connection in each workload account and configure BGP to advertise the on-premises routes.

    Why it's wrong here

    A Site-to-Site VPN requires a virtual private gateway or transit gateway in each VPC and terminates on a customer gateway. Running 200 VPNs over one Direct Connect connection adds unnecessary configuration and cost, and the Direct Connect connection already terminates in the networking account, so this duplicates connectivity rather than centralizing it.

  • ✗

    Create a VPC peering connection between the shared services VPC and each workload VPC, and propagate the Direct Connect routes through a static route in each workload VPC route table.

    Why it's wrong here

    VPC peering is non-transitive, so a workload VPC peered only with the shared services VPC cannot use the Direct Connect connection unless the shared services VPC performs routing or NAT, which is not described. Creating 200 peering connections also increases management overhead, contrary to the requirement to minimize operational effort.

  • ✓

    Create a transit gateway in the networking account, attach the Direct Connect gateway and all workload VPCs to it, and share the transit gateway using AWS Resource Access Manager.

    Why this is correct

    A transit gateway in the networking account can attach the Direct Connect gateway and all workload VPCs, and AWS Resource Access Manager lets other accounts in the organization attach their VPCs to the shared transit gateway. This centralizes connectivity, avoids a full mesh of peering connections, and scales to hundreds of accounts at lower operational cost.

  • ✗

    Use AWS PrivateLink to create interface VPC endpoints in each workload VPC that point to the on-premises services in the networking account.

    Why it's wrong here

    AWS PrivateLink provides private connectivity to specific services, not general network routing to an on-premises data center. It cannot carry arbitrary IP traffic from workload VPCs to on-premises subnets, so it does not satisfy the requirement to reach the data center over the existing Direct Connect connection.

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.