Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A global company uses AWS Organizations with hundreds of accounts. The networking team needs to allow VPCs in different accounts to communicate privately using AWS Transit Gateway. The company wants to centralize management while allowing individual account owners to create and attach VPCs. Which solution meets these requirements?

⚠ Common exam trap

Candidates often confuse AWS PrivateLink (which is for service exposure, not general routing) with Transit Gateway, or assume VPC peering can be scaled via a central VPC, failing to recognize that peering is non-transitive and requires a full mesh for multi-VPC connectivity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Transit Gateway in the networking account and share it with other accounts using AWS Resource Access Manager.

AWS Transit Gateway allows you to centralize network connectivity across multiple VPCs and accounts. By creating the Transit Gateway in the networking account and sharing it via AWS Resource Access Manager (RAM), you enable individual account owners to attach their VPCs to the shared Transit Gateway, achieving private communication while maintaining centralized management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a VPN connection from each VPC to a central network appliance.

    Why it's wrong here

    A VPN from each VPC to a central appliance routes traffic over IPsec tunnels through a self-managed instance, adding bandwidth, availability and scaling limits, and it does not let account owners attach VPCs to a managed hub. Site-to-site VPN suits hybrid on-premises connectivity, not intra-AWS multi-account routing.

  • ✗

    Use AWS PrivateLink to connect each VPC to a central VPC endpoint service.

    Why it's wrong here

    AWS PrivateLink exposes specific services through interface endpoints; it does not provide transitive VPC-to-VPC routing, so VPCs cannot reach each other's resources. It is tempting because it connects VPCs privately across accounts, but it is designed for consuming a published service, not building a routed network topology.

  • ✓

    Create a Transit Gateway in the networking account and share it with other accounts using AWS Resource Access Manager.

    Why this is correct

    AWS Resource Access Manager shares the Transit Gateway from the networking account to other accounts or the organisation, letting individual owners create and attach their own VPC attachments while the networking team retains central ownership and management.

  • ✗

    Create VPC peering connections between each VPC and a central VPC.

    Why it's wrong here

    VPC peering is one-to-one and non-transitive, so hundreds of accounts would need a full mesh of connections, which cannot be centrally managed or scaled. It is tempting because peering is simple for a handful of VPCs, but it fails the requirement that account owners attach their own VPCs to a shared transit hub.

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.