Courseiva
Design for New Solutions →hardMultiple Choice

SAP-C02 Design for New Solutions Practice Question

A company is designing a new hybrid cloud solution that requires low-latency access to on-premises data from AWS. The connection must be highly available and encrypted. The company has multiple VPCs and on-premises locations. Which combination of services meets these requirements?

⚠ Common exam trap

Candidates often assume a single VPN or Direct Connect alone is sufficient, but the question requires both low latency (Direct Connect) and encryption (VPN) across multiple VPCs and on-premises sites, which only Transit Gateway with Direct Connect and VPN backup fully satisfies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Transit Gateway and AWS Direct Connect with VPN backup

AWS Transit Gateway acts as a central hub to interconnect multiple VPCs and on-premises networks, simplifying the hybrid architecture. AWS Direct Connect provides a private, low-latency, and consistent network path, while a Site-to-Site VPN over the Direct Connect link (or as a separate backup) adds encryption and high availability. This combination meets all requirements: low latency (Direct Connect), encryption (VPN), high availability (dual connections or failover), and support for multiple VPCs and on-premises locations (Transit Gateway).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Site-to-Site VPN and VPC Endpoints

    Why it's wrong here

    VPC endpoints connect privately to AWS services within a VPC; they do not link on-premises networks to AWS. Hybrid connectivity with encryption and redundancy needs AWS Site-to-Site VPN paired with AWS Transit Gateway or Direct Connect. Endpoints suit private access to S3 or DynamoDB from inside AWS.

  • ✓

    AWS Transit Gateway and AWS Direct Connect with VPN backup

    Why this is correct

    Transit Gateway provides a hub-and-spoke model for multiple VPCs and on-premises networks. Direct Connect offers dedicated low-latency connections with encryption, and VPN provides a backup.

  • ✗

    VPC Peering and AWS Site-to-Site VPN

    Why it's wrong here

    VPC peering only interconnects VPCs, so it cannot reach on-premises locations at all; the Site-to-Site VPN alone terminates at a single virtual private gateway, giving no multi-location redundancy. Site-to-Site VPN suits a single encrypted tunnel between one on-premises site and one VPC, which is why pairing it with peering is tempting here.

  • ✗

    AWS Client VPN and VPC Peering

    Why it's wrong here

    AWS Client VPN terminates remote-user sessions, not site-to-site links between on-premises networks and multiple VPCs, so it cannot provide the required hybrid connectivity. It is tempting because it encrypts traffic and integrates with Microsoft Entra ID for user authentication, making it the right choice when individual remote workers need access to VPC resources.

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.