Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A financial services company has an AWS Organizations structure with a management account, a dedicated Network account, and 40 workload accounts. The Network team wants to share a single AWS Transit Gateway with all workload accounts so that each account can attach its own VPCs. Workload accounts must not be able to modify the Transit Gateway route tables owned by the Network account. Which combination of actions should a solutions architect take to meet these requirements with the LEAST operational overhead?

⚠ Common exam trap

The trap here is assuming that sharing a Transit Gateway via AWS RAM also shares administrative control of its route tables, when in fact ownership and route table modification rights remain with the owner account.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create the Transit Gateway in the Network account and use AWS Resource Access Manager (AWS RAM) to share it with the organization. In each workload account, create a transit gateway attachment for the VPC and associate it with the shared transit gateway route table.

AWS RAM is the native mechanism to share a Transit Gateway across an organization. The owner account keeps control of the Transit Gateway and its route tables, while participant accounts create VPC attachments. This satisfies both the sharing requirement and the restriction that workload accounts cannot alter Network-owned route tables, with minimal ongoing administration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a separate Transit Gateway in each workload account and peer them together using static routes in each account's route tables.

    Why it's wrong here

    Creating one Transit Gateway per workload account introduces 40 gateways to manage and peer, multiplying configuration and cost. Peering Transit Gateways also requires careful non-overlapping CIDR planning and manual route propagation. It does not enforce central control over route tables and creates significant operational overhead, which the scenario explicitly wants to avoid.

  • ✗

    Create the Transit Gateway in the Network account and create a VPC peering connection from each workload VPC to a shared services VPC that hosts the Transit Gateway.

    Why it's wrong here

    VPC peering to a shared services VPC does not provide Transit Gateway attachment semantics, so workload VPCs cannot use the Transit Gateway route tables directly. It also scales poorly because each peering connection must be accepted and maintained, and route propagation is manual. This fails the requirement to let each account attach its own VPCs to the shared Transit Gateway.

  • ✗

    Create the Transit Gateway in the management account and grant each workload account an IAM role that allows creating attachments in the management account.

    Why it's wrong here

    Placing the Transit Gateway in the management account conflicts with AWS best practice of keeping the management account free of workload resources, and cross-account attachment creation still requires resource sharing. Granting workload accounts roles in the management account broadens blast radius and does not by itself prevent modification of route tables owned by the Network team.

  • ✓

    Create the Transit Gateway in the Network account and use AWS Resource Access Manager (AWS RAM) to share it with the organization. In each workload account, create a transit gateway attachment for the VPC and associate it with the shared transit gateway route table.

    Why this is correct

    Sharing the Transit Gateway through AWS RAM with the organization allows every workload account to create attachments without duplicating the Transit Gateway. The Network account retains ownership of the route tables, so workload accounts can associate attachments but cannot modify the Network-owned route tables unless explicitly granted. This minimizes overhead and preserves the required boundaries.

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.