Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A financial services company has an AWS Organizations structure with a management account, a dedicated network account, and 40 workload accounts. Each workload account has its own VPC, and all VPCs must be able to reach a shared services VPC in the network account. The security team requires that all inter-VPC traffic be inspected by a central firewall appliance before reaching the shared services. Which solution meets these requirements with the LEAST operational overhead?

⚠ Common exam trap

The trap here is assuming that VPC peering or PrivateLink can provide centralized traffic inspection, when they are either non-transitive or service-specific and cannot force all traffic through a firewall.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach all workload VPCs to a central AWS Transit Gateway in the network account, use a separate route table for the shared services VPC, and associate a firewall appliance VPC with a dedicated inspection route table.

A central AWS Transit Gateway with separate route tables allows all workload VPCs to route traffic through a firewall VPC in the network account before reaching shared services. This hub-and-spoke inspection model is scalable, requires minimal per-account configuration, and meets the security requirement for central inspection. Other options either lack transitivity, do not enforce inspection, or are not designed for inter-VPC routing at scale.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS PrivateLink to expose the shared services as endpoint services, and have each workload VPC create an interface VPC endpoint to access them.

    Why it's wrong here

    AWS PrivateLink provides private connectivity to specific services, but it does not allow centralized inspection of all inter-VPC traffic. It is unidirectional and service-specific, and cannot enforce a firewall appliance in the path for arbitrary traffic between VPCs. This does not satisfy the requirement for inspection of all inter-VPC traffic.

  • ✗

    Deploy a VPN connection from each workload VPC to the shared services VPC using AWS Site-to-Site VPN, and route traffic through the VPN tunnels.

    Why it's wrong here

    Site-to-Site VPN is designed for connecting on-premises networks to AWS, not for inter-VPC routing within AWS. Using it between VPCs would require virtual private gateways or transit gateways, and it adds significant complexity and cost per VPC. It does not provide a scalable or low-overhead solution for 40 accounts.

  • ✗

    Create a VPC peering connection between each workload VPC and the shared services VPC, and route traffic through the shared services VPC where a firewall appliance is deployed.

    Why it's wrong here

    VPC peering is non-transitive and requires a full mesh or hub-and-spoke with separate peering connections per VPC, plus route table entries in every VPC. It cannot force traffic through a central firewall without complex routing and does not scale well to 40 accounts. This increases operational overhead and does not meet the central inspection requirement cleanly.

  • ✓

    Attach all workload VPCs to a central AWS Transit Gateway in the network account, use a separate route table for the shared services VPC, and associate a firewall appliance VPC with a dedicated inspection route table.

    Why this is correct

    AWS Transit Gateway provides transitive routing and centralized management. By using separate route tables and associating the firewall VPC with an inspection route table, traffic from workload VPCs can be forced through the firewall before reaching the shared services VPC. This is the standard hub-and-spoke inspection pattern and scales to many accounts with minimal per-VPC configuration.

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.