Courseiva

SAP-C02 Practice Question: Accelerate Workload Migration and Modernization

A company is migrating a Windows-based .NET application to AWS. The application uses SQL Server for its database and stores documents on a Windows file share. The company wants to adopt a hybrid model initially, where the application runs on AWS but still connects to on-premises resources for legacy integration. The migration must use a phased approach: first move the compute to AWS, then the database, and finally the file storage. The company has high latency to the internet and wants to optimize data transfer. You have set up a Direct Connect connection. During the first phase, you migrate the web and application servers to Amazon EC2 Windows instances. You need to ensure that the EC2 instances can access the on-premises SQL Server and file share securely. Which combination of actions should be taken?

⚠ Common exam trap

SAP-C02 often tests whether candidates understand that NAT gateways and VPC peering do not provide on-premises connectivity — only Direct Connect or VPN can bridge AWS to a corporate data center.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Place the EC2 instances in a private subnet. Create a VPN connection or use Direct Connect virtual interface to connect to on-premises. Configure security groups to allow traffic to on-premises SQL Server and file share.

Placing EC2 instances in a private subnet keeps them off the public internet while still allowing outbound access through the VPC route table. A Direct Connect virtual interface (private VIF) or a VPN connection provides private, low-latency connectivity to on-premises SQL Server and file share, and security groups can be scoped to allow only the required SQL (1433) and SMB (445) traffic. This matches the hybrid, phased migration model where compute moves first but still depends on on-premises data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Place the EC2 instances in a private subnet. Create a VPN connection or use Direct Connect virtual interface to connect to on-premises. Configure security groups to allow traffic to on-premises SQL Server and file share.

    Why this is correct

    Private subnets plus a Direct Connect virtual interface or VPN give the EC2 instances private, encrypted connectivity to on-premises SQL Server and file share, avoiding internet exposure. Security groups then restrict traffic to only those on-premises endpoints, meeting the secure hybrid-access requirement.

  • ✗

    Place the EC2 instances in a private subnet with a NAT gateway. Use VPC peering to on-premises.

    Why it's wrong here

    A NAT gateway provides outbound internet access only and cannot route to on-premises; VPC peering does not connect to on-premises networks, which requires a virtual private gateway or Transit Gateway over the Direct Connect link. It is tempting as a private-connectivity pattern, and would be correct for VPC-to-VPC peering.

  • ✗

    Place the EC2 instances in a public subnet. Use an internet gateway and configure security groups to allow inbound traffic from on-premises IPs.

    Why it's wrong here

    A public subnet with an internet gateway routes traffic over the public internet, ignoring the Direct Connect connection and exposing database and file-share traffic. It is tempting because it is quick to configure, and would be correct for publicly accessible web servers, not private hybrid access to on-premises SQL Server.

  • ✗

    Use Amazon EC2-Classic and link the instances to on-premises via ClassicLink.

    Why it's wrong here

    EC2-Classic is retired and ClassicLink only linked classic instances to a VPC, not to on-premises networks; neither supports the Direct Connect path required here. It is tempting as a legacy hybrid-connectivity term, and would have been correct for connecting EC2-Classic instances to a VPC in older accounts.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.