SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company has a multi-account AWS environment with a centralized network account that hosts a transit gateway. The company wants to share the transit gateway with multiple member accounts. Which AWS service should be used to share the transit gateway?
⚠ Common exam trap
A common mix-up: candidates confuse VPC peering (which is point-to-point and non-transitive) with transit gateway sharing via RAM, which provides transitive routing and centralized management across multiple accounts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Resource Access Manager (RAM)
AWS Resource Access Manager (RAM) enables you to share a transit gateway owned by a central network account with other AWS accounts in your organization. This eliminates the need to create separate transit gateway attachments or VPC peering connections, simplifying network architecture and reducing operational overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Resource Access Manager (RAM)
Why this is correct
AWS Resource Access Manager is the only service that natively shares a transit gateway across accounts, satisfying the centralised network account requirement. It lets the owner account specify which member accounts may attach VPCs, avoiding duplicated TGWs or peering.
- ✗
AWS PrivateLink
Why it's wrong here
AWS PrivateLink exposes a service endpoint to consumers within a VPC, not a transit gateway attachment across accounts. It is tempting because PrivateLink privately connects services between VPCs and accounts, which suits publishing an internal application endpoint, but it cannot share a transit gateway for inter-VPC routing.
- ✗
VPC peering connection
Why it's wrong here
VPC peering connects two VPCs directly and does not share a transit gateway with member accounts. It is tempting because peering links VPCs across accounts, which suits simple point-to-point connectivity between a handful of VPCs, but it cannot attach member VPCs to a central transit gateway.
- ✗
AWS Direct Connect
Why it's wrong here
AWS Direct Connect provides dedicated private connectivity from on-premises networks into AWS and does not share a transit gateway between accounts. It is tempting because Direct Connect integrates with transit gateways for hybrid routing, which suits linking a data centre to many VPCs, but it is not an account-sharing mechanism.
Go deeper
Related to this question
About these practice questions
This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.