Courseiva
Design Solutions for Organizational ComplexitymediumMultiple ChoiceObjective-mapped

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company uses AWS Organizations with 50 accounts. The networking team wants to deploy a shared VPC in the network account and share subnets with other accounts. The shared subnets will host EC2 instances from the consuming accounts. What is the MOST secure way to ensure that only authorized accounts can create resources in the shared subnets?

⚠ Common exam trap

Watch out — candidates often confuse network connectivity solutions (like Transit Gateway or VPC Peering) with resource sharing and authorization mechanisms, leading them to select options that enable traffic flow but do not control which accounts can create resources in shared subnets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use AWS Resource Access Manager to share subnets with specific accounts and require that the consuming account uses a service-linked role.

AWS Resource Access Manager (RAM) allows the network account to share subnets with specific consuming accounts, and requiring a service-linked role ensures that only authorized accounts can launch resources in those subnets. This approach provides granular, cross-account subnet sharing without exposing the VPC to unauthorized actions, aligning with the principle of least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use AWS Transit Gateway to route traffic between accounts and rely on route tables to control access.

    Why it's wrong here

    Transit Gateway does not provide subnet-level sharing; it only routes traffic.

  • Use AWS Resource Access Manager to share subnets with specific accounts and require that the consuming account uses a service-linked role.

    Why this is correct

    RAM provides fine-grained sharing and the service-linked role ensures secure creation of resources.

  • Create VPC Peering connections between the network account and each consuming account, and use security groups to restrict access.

    Why it's wrong here

    VPC Peering does not allow subnet sharing; it connects VPCs at the network layer.

  • Create an SCP that denies ec2:RunInstances unless the subnet is in the network account.

    Why it's wrong here

    SCPs cannot condition on subnet ownership across accounts; they apply to the entire account.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This SAP-C02 question is part of Courseiva's 1,660-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.