SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company has a multi-account AWS environment with a central shared services VPC and multiple workload VPCs connected via AWS Transit Gateway. The security team wants to inspect all traffic between workload VPCs using a centralized firewall appliance in the shared services VPC. They need to ensure that traffic is inspected without modifying the workload VPC route tables. What should they do?
⚠ Common exam trap
The trap here is overlooking the need for appliance mode on the Transit Gateway attachment to maintain flow symmetry for stateful inspection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure AWS Transit Gateway route tables to send all inter-VPC traffic to the shared services VPC, and enable appliance mode on the Transit Gateway attachment for the shared services VPC.
To inspect traffic between workload VPCs without modifying their route tables, you can use AWS Transit Gateway route tables to direct traffic to a central shared services VPC. Enabling appliance mode on the Transit Gateway attachment for the shared services VPC ensures that flow symmetry is maintained for stateful inspection. This solution is scalable and does not require changes to workload VPC route tables.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a VPC peering connection between each workload VPC and the shared services VPC, and update the route tables in each workload VPC to point to the shared services VPC for inter-VPC traffic.
Why it's wrong here
VPC peering requires modifying route tables in each workload VPC to direct traffic to the shared services VPC. This violates the requirement to not modify workload VPC route tables. Additionally, VPC peering does not support transitive routing, so traffic between workload VPCs would not be inspected unless each VPC is peered with the shared services VPC, which is complex and not scalable.
- ✓
Configure AWS Transit Gateway route tables to send all inter-VPC traffic to the shared services VPC, and enable appliance mode on the Transit Gateway attachment for the shared services VPC.
Why this is correct
By configuring Transit Gateway route tables to direct traffic to the shared services VPC and enabling appliance mode on that attachment, traffic between workload VPCs will be routed through the firewall appliance. Appliance mode ensures that flow symmetry is maintained for stateful inspection, and workload VPC route tables do not need to be modified.
- ✗
Use AWS PrivateLink to create endpoint services in the shared services VPC for each workload VPC, and configure the workload VPCs to use these endpoints for inter-VPC communication.
Why it's wrong here
AWS PrivateLink is designed for one-way access to services, not for inspecting traffic between VPCs. It does not provide a way to route all inter-VPC traffic through a central appliance. PrivateLink endpoints are for specific services, and they do not support transitive routing or traffic inspection between VPCs. This approach would not meet the requirement.
- ✗
Configure AWS Transit Gateway route tables to send all inter-VPC traffic to the shared services VPC, and disable appliance mode on the Transit Gateway attachment for the shared services VPC.
Why it's wrong here
Disabling appliance mode on the Transit Gateway attachment can cause asymmetric routing for stateful inspection appliances. Appliance mode is specifically designed to maintain flow symmetry by ensuring that return traffic is routed to the same appliance. Without it, the firewall may drop packets due to asymmetric flows, breaking connectivity.
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.