SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company has a multi-account AWS environment with a central shared services VPC in a networking account. They want to allow resources in workload accounts to access a shared Amazon RDS database in the shared services VPC. The RDS database is in a private subnet. The company uses AWS Transit Gateway to connect all VPCs. They have set up a route in the workload VPC route table pointing to the Transit Gateway for the shared services VPC CIDR. However, resources in the workload accounts cannot connect to the RDS database. What is the most likely cause?
⚠ Common exam trap
The trap here is focusing only on the forward path and forgetting that return traffic requires a route in the destination subnet's route table.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The route table associated with the subnet where the RDS database resides does not have a route back to the workload VPC CIDR via the Transit Gateway.
When connecting VPCs through a Transit Gateway, routing must be symmetric. The workload VPC has a route to the Transit Gateway for the shared services VPC CIDR, but the shared services VPC subnet's route table must also have a route back to the workload VPC CIDR via the Transit Gateway. Without this return route, the response packets cannot find their way back, and the connection fails. This is a common pitfall in multi-VPC designs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The security group on the RDS database does not allow inbound traffic from the workload VPC CIDR.
Why it's wrong here
Security groups are stateful and can reference CIDR blocks or other security groups. If the security group does not allow inbound traffic from the workload VPC CIDR, connections would be blocked. This is a common issue, but the scenario implies that routing is set up. The question asks for the most likely cause given that routing is configured. Without more information, this is plausible, but the key detail is that the RDS database is in a private subnet and the workload accounts are in different VPCs. The most likely cause is that the route table for the subnet where the RDS database resides does not have a route back to the workload VPC CIDR via the Transit Gateway.
- ✓
The route table associated with the subnet where the RDS database resides does not have a route back to the workload VPC CIDR via the Transit Gateway.
Why this is correct
For traffic to flow between VPCs through a Transit Gateway, both the source and destination subnets must have route table entries pointing to the Transit Gateway for the other VPC's CIDR. The workload VPC has a route to the shared services VPC, but the shared services VPC subnet's route table may lack a route back to the workload VPC CIDR. This asymmetric routing causes the return traffic to be dropped, preventing the connection.
- ✗
The Transit Gateway attachment for the shared services VPC is not associated with the correct Transit Gateway route table.
Why it's wrong here
Transit Gateway route tables control which attachments can route to each other. If the shared services VPC attachment is not associated with a route table that has a route to the workload VPC attachment, traffic would be dropped. However, the scenario states that the workload VPC has a route to the Transit Gateway for the shared services CIDR, implying that the Transit Gateway route table likely has a route to the shared services VPC. The missing piece is often the return route in the shared services subnet route table.
- ✗
The RDS database is not publicly accessible, and the workload resources are using public IP addresses.
Why it's wrong here
The RDS database is in a private subnet and should not be publicly accessible. Workload resources should use private IP addresses when communicating over a Transit Gateway. If they are using public IP addresses, the traffic would not route through the Transit Gateway. However, the scenario does not indicate that workload resources are using public IPs; it focuses on routing configuration. The most likely cause is the missing return route.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.