Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company has a VPC with a CIDR block of 10.0.0.0/16. They need to connect this VPC to an on-premises network that uses the CIDR block 10.0.0.0/8. The company wants to use AWS Site-to-Site VPN for the connection. They must avoid IP address conflicts. What is the MOST appropriate solution?

⚠ Common exam trap

The trap here is assuming that AWS Transit Gateway or VPN configurations can automatically resolve overlapping CIDR blocks, but they cannot; the only true fix is to use non-overlapping IP ranges.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Re-create the VPC with a non-overlapping CIDR block, such as 192.168.0.0/16, and then establish the Site-to-Site VPN.

IP address conflicts between a VPC and on-premises networks can cause routing failures and unpredictable behavior. The most appropriate solution is to use non-overlapping CIDR blocks. Re-creating the VPC with a CIDR that does not overlap with the on-premises 10.0.0.0/8 network ensures clean routing and avoids the need for complex NAT or translation. While migration may be required, it is the most reliable long-term fix.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Transit Gateway with a Site-to-Site VPN attachment and enable route propagation.

    Why it's wrong here

    AWS Transit Gateway does not resolve IP address conflicts. If the on-premises network uses 10.0.0.0/8 and the VPC uses 10.0.0.0/16, the overlapping addresses will cause routing issues. Transit Gateway alone cannot translate or avoid the conflict; additional measures like NAT are required.

  • ✗

    Configure the Site-to-Site VPN with static routes and use AWS PrivateLink to access on-premises services.

    Why it's wrong here

    AWS PrivateLink is used to privately access services in other VPCs or on-premises via VPC endpoints, but it does not provide full network connectivity or resolve CIDR overlaps. Static routes on the VPN will not prevent conflicts. This solution does not address the overlapping IP ranges.

  • ✗

    Use AWS Site-to-Site VPN with a virtual private gateway and implement NAT on the on-premises side to translate the VPC CIDR to a non-overlapping range.

    Why it's wrong here

    NAT on the on-premises side can translate addresses, but it requires careful configuration and may not be supported for all traffic. It also adds complexity. However, it is a valid approach if you cannot change the VPC CIDR. But is it the MOST appropriate? The question says 'avoid IP address conflicts' and 'MOST appropriate solution'. Another option might be better.

  • ✓

    Re-create the VPC with a non-overlapping CIDR block, such as 192.168.0.0/16, and then establish the Site-to-Site VPN.

    Why this is correct

    The most straightforward way to avoid IP address conflicts is to ensure that the VPC CIDR does not overlap with the on-premises network. Re-creating the VPC with a non-overlapping CIDR like 192.168.0.0/16 eliminates the conflict entirely. While this may require migration effort, it is the most reliable and recommended solution for overlapping CIDRs.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.