Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A financial services company uses AWS Organizations with a central networking account. Workload accounts need to reach an on-premises data center over AWS Site-to-Site VPN, and the network team wants to enforce that all inter-VPC traffic flows through a central inspection VPC. Which combination of components should the network team deploy to route traffic through the inspection VPC while keeping the architecture scalable?

⚠ Common exam trap

The trap here is reaching for VPC peering or PrivateLink for general inter-VPC and on-premises routing when only a transit gateway provides transitive, centrally governed connectivity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Transit Gateway with a central transit gateway in the networking account, attach the inspection VPC and workload VPCs to it, and use a separate route table per segment with the inspection VPC as the next hop.

A single central AWS Transit Gateway in the networking account, with workload VPC attachments and segment-specific route tables pointing to the inspection VPC, delivers scalable hub-and-spoke routing and centralized inspection. Attaching the Site-to-Site VPN to the same transit gateway keeps on-premises traffic in the same controlled path and avoids per-account VPN or peering sprawl.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a VPC peering mesh between all workload VPCs and the inspection VPC, and attach a virtual private gateway to each workload VPC.

    Why it's wrong here

    Full-mesh VPC peering does not scale to many accounts, has no transitive routing, and each peering connection must be managed individually. Attaching a virtual private gateway to every workload VPC also multiplies VPN endpoints and bypasses the central inspection design, defeating the requirement that traffic flow through the inspection VPC.

  • ✗

    Use AWS PrivateLink endpoints in each workload VPC to reach the inspection VPC, and route on-premises traffic through the endpoints.

    Why it's wrong here

    AWS PrivateLink exposes specific services over interface endpoints and does not provide general IP routing between VPCs or to on-premises networks. It cannot carry arbitrary workload traffic to the inspection VPC or the data center, so it fails to satisfy the centralized inspection and VPN connectivity requirements.

  • ✗

    Create a transit gateway in each workload account and peer the transit gateways together, then attach the VPN to one of them.

    Why it's wrong here

    Peering many transit gateways creates a complex mesh with per-peer route tables and limited route propagation, which is harder to govern than a single central transit gateway. It also scatters policy across accounts and does not cleanly enforce that all traffic traverses one inspection VPC before reaching on-premises.

  • ✓

    Use AWS Transit Gateway with a central transit gateway in the networking account, attach the inspection VPC and workload VPCs to it, and use a separate route table per segment with the inspection VPC as the next hop.

    Why this is correct

    A central transit gateway provides hub-and-spoke connectivity with transitive routing, and separate transit gateway route tables let the network team force traffic through the inspection VPC. Attaching the VPN to the transit gateway keeps on-premises access centralized while scaling to many workload accounts without per-pair peering.

About these practice questions

This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.