SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company is designing a multi-account strategy for its development teams. Each team needs to have its own isolated environment with VPCs, subnets, and security groups. The company wants to centralize network administration and ensure that all VPCs use a common set of security rules. Which THREE steps should the company take? (Choose THREE.)
⚠ Common exam trap
Watch out — candidates often confuse AWS CloudFormation StackSets (which only automates resource deployment) with centralized security enforcement, overlooking the need for a hub-and-spoke architecture with a centralized inspection point like AWS Network Firewall and Transit Gateway.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a centralized inspection VPC with AWS Network Firewall and use Transit Gateway to route traffic.
Option B is correct because a centralized inspection VPC with AWS Network Firewall, combined with AWS Transit Gateway for routing, provides centralized traffic inspection and a hub-and-spoke topology that enforces common security policy across all team VPCs. Option C is correct because a dedicated network account using AWS Resource Access Manager (RAM) to share subnets lets teams consume centrally managed VPC networking while keeping network administration centralized. Option E is correct because AWS Firewall Manager applies common security group rules (and other policies) across all accounts in AWS Organizations, ensuring uniform security rules. Option A is not correct because VPC Peering is a point-to-point connection that does not scale for centralized administration or common security enforcement across many accounts. Option D is not correct because CloudFormation StackSets deploys identical VPCs per account, which duplicates network administration rather than centralizing it and does not enforce common security rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow each team to create their own VPCs and use VPC Peering to connect them.
Why it's wrong here
Team-created VPCs with peering leave administration distributed and security rules duplicated per VPC, contradicting centralised control. Peering suits connecting a small number of specific VPCs for direct traffic, not enforcing uniform rules across a multi-account estate.
- ✓
Deploy a centralized inspection VPC with AWS Network Firewall and use Transit Gateway to route traffic.
Why this is correct
A centralised inspection VPC with AWS Network Firewall enforces one common rule set across every team's VPC, satisfying the requirement for shared security rules. Transit Gateway hubs the isolated VPCs together, letting traffic route through that inspection point while network administration stays centralised.
- ✓
Create a dedicated network account and use AWS Resource Access Manager to share subnets with other accounts.
Why this is correct
AWS Resource Access Manager shares subnets from a central network account into participant accounts, so each team deploys resources into shared VPC subnets while the network account retains ownership and control. This satisfies the requirement to centralise network administration, since security groups and subnet configuration stay managed in one place rather than duplicated per team.
- ✗
Use AWS CloudFormation StackSets to deploy identical VPCs to each account.
Why it's wrong here
StackSets replicate resources but do not centralise network administration; each account still owns and edits its own VPC and security groups, so common rules drift. StackSets suit deploying identical baseline templates across many accounts, not sharing centrally governed networks.
- ✓
Use AWS Firewall Manager to apply common security group rules across all accounts.
Why this is correct
AWS Firewall Manager enforces security group policies centrally across every account in an AWS Organization, satisfying the requirement for a common set of security rules. Policies apply automatically to existing and newly created VPCs, so each team's isolated environment inherits the same protections without per-account configuration.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.