SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company has multiple AWS accounts and wants to share a centrally managed Amazon VPC subnet for workloads that require low latency. The VPC is in the networking account. Which solution meets these requirements with the LEAST operational overhead?
⚠ Common exam trap
The trap here is that candidates often overcomplicate the solution by choosing Transit Gateway or VPC peering, thinking they need to interconnect VPCs, when the simplest and most cost-effective approach is to share the existing subnet directly using AWS RAM.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Resource Access Manager (RAM) to share the subnet with the workload accounts.
AWS Resource Access Manager (RAM) allows you to share a subnet from a central VPC in the networking account with other AWS accounts without creating separate VPCs or complex networking. This enables workload accounts to launch resources directly into the shared subnet, achieving low latency by keeping them in the same VPC and Availability Zone. RAM handles the cross-account sharing with minimal operational overhead, as it does not require additional network appliances or routing configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a separate VPC in each account and connect them with VPC peering.
Why it's wrong here
Separate VPCs joined by peering cannot share a subnet, and replicating subnets per account adds address-management overhead. It is tempting because peering links isolated VPCs, and would be correct for connecting a few VPCs with non-overlapping CIDRs where subnet sharing is not required.
- ✓
Use AWS Resource Access Manager (RAM) to share the subnet with the workload accounts.
Why this is correct
AWS RAM shares the existing subnet in place, so workload accounts launch resources directly into it without duplicating VPCs or peering. This satisfies the low-latency requirement because resources remain in one subnet, and it minimises operational overhead since no additional networking infrastructure is provisioned or maintained.
- ✗
Set up an AWS Transit Gateway and attach the VPCs from each account.
Why it's wrong here
Transit Gateway routes traffic between VPCs over its hub, adding attachment and route-table management plus extra hops; it does not share a subnet. It is tempting because it centrally connects many VPCs, and would be correct for large-scale many-to-many connectivity rather than low-latency subnet sharing.
- ✗
Create VPC peering connections between the networking account and each workload account.
Why it's wrong here
VPC peering connects separate VPCs but never shares a subnet, and each new account needs its own peering connection and routes. It is tempting because it is simple for a small number of VPCs, and would be correct for point-to-point connectivity between two VPCs without shared subnets.
Visual reference
Go deeper
Related to this question
About these practice questions
This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.