SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company needs to share a VPC subnet with multiple accounts in the same AWS Organization. What is the MOST secure way to achieve this?
⚠ Common exam trap
Watch out — candidates often confuse network connectivity solutions (Transit Gateway, VPC peering, VPN) with resource sharing, assuming that to 'share' a subnet you must connect the VPCs, when in fact AWS RAM provides a direct, secure, and managed way to share subnets without any network-level interconnection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS RAM to share the subnet with the organization.
AWS Resource Access Manager (RAM) allows you to share a subnet with other accounts within the same AWS Organization without requiring any intermediate networking appliances or complex routing. This is the most secure approach because the shared subnet remains under the VPC owner's administrative control, and participating accounts can launch resources directly into the subnet while inheriting the VPC's security policies. No traffic traverses external connections or third-party devices, reducing the attack surface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a Transit Gateway and attach all accounts.
Why it's wrong here
A Transit Gateway is a routing hub connecting VPCs and on-premises networks; it forwards traffic between networks but does not let other accounts launch resources inside the owner's subnet. It is tempting because it centralises connectivity at scale, and would be correct for hub-and-spoke routing rather than subnet sharing.
- ✗
Set up a VPN connection between accounts.
Why it's wrong here
A VPN connection encrypts traffic between networks but provides no mechanism for another account to place resources within the owner's subnet. It is tempting because encryption sounds secure, and would be correct for connecting remote networks or on-premises sites, not for sharing subnet address space across accounts.
- ✓
Use AWS RAM to share the subnet with the organization.
Why this is correct
AWS RAM shares the subnet in place, so participant accounts launch resources directly into it without duplicating networking or peering. Sharing within the organisation enables automatic acceptance and centralised governance, satisfying the secure multi-account requirement more tightly than VPC peering or duplicated subnets.
- ✗
Create a VPC peering connection between each account and the VPC owner.
Why it's wrong here
VPC peering connects networks but does not share a subnet's address space with other accounts, so participants cannot launch resources into the owner's subnet. It is tempting because peering is private and avoids public exposure, and would be correct for routing traffic between separate VPCs rather than shared-subnet participation.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.