SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A healthcare company operates a multi-account AWS environment with a shared services VPC in a central account. Workload accounts need to access a centralized Amazon RDS for MySQL database in the shared services VPC. The security team requires that all database traffic be encrypted in transit and that no workload account can access the database directly from the internet. They also want to minimize administrative overhead. Which solution meets these requirements?
⚠ Common exam trap
The trap here is assuming that AWS PrivateLink can be used for Amazon RDS, but RDS is not a supported endpoint service for interface VPC endpoints.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set up an AWS Transit Gateway with a central attachment in the shared services VPC, attach all workload VPCs, and configure the RDS security group to allow traffic only from the workload CIDR ranges over SSL/TLS.
AWS Transit Gateway provides a scalable, centralized hub for connecting many VPCs across accounts, which minimizes administrative overhead compared to a mesh of VPC peering connections. By routing traffic through the transit gateway to the shared services VPC, workload accounts can access the RDS instance privately. Enforcing SSL/TLS on the RDS instance and restricting the security group to workload CIDRs ensures encryption in transit and prevents internet access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS PrivateLink to create an interface VPC endpoint for RDS in each workload VPC, and enforce SSL/TLS on the RDS instance.
Why it's wrong here
AWS PrivateLink does not support Amazon RDS directly; RDS is not a supported endpoint service for interface VPC endpoints. You cannot create a PrivateLink endpoint for RDS. Therefore, this solution is technically invalid. While PrivateLink is useful for many services, it cannot be used to access RDS in this manner, making this option incorrect.
- ✗
Deploy an Application Load Balancer in the shared services VPC, register the RDS instance as a target, and have workload accounts connect through the ALB using SSL/TLS.
Why it's wrong here
Application Load Balancers operate at the application layer and do not support TCP passthrough for database protocols like MySQL. You cannot register an RDS instance as a target for an ALB. This approach is technically infeasible. Additionally, it would introduce unnecessary complexity and potential security risks, and it does not meet the requirement for direct, secure database connectivity.
- ✗
Create a VPC peering connection between each workload VPC and the shared services VPC, and configure the RDS instance to require SSL/TLS connections.
Why it's wrong here
VPC peering provides private connectivity, but it requires a full mesh of peering connections if workload VPCs need to communicate with each other, increasing complexity. More importantly, VPC peering does not scale well for many accounts and does not centralize management. While SSL/TLS can be enforced on RDS, the peering approach adds administrative overhead as accounts grow, contradicting the requirement to minimize overhead.
- ✓
Set up an AWS Transit Gateway with a central attachment in the shared services VPC, attach all workload VPCs, and configure the RDS security group to allow traffic only from the workload CIDR ranges over SSL/TLS.
Why this is correct
AWS Transit Gateway provides a hub-and-spoke model that scales to many VPCs and accounts, centralizing connectivity and reducing administrative overhead. By attaching workload VPCs to the transit gateway and routing to the shared services VPC, traffic stays private. Enforcing SSL/TLS on the RDS instance and restricting the security group to workload CIDRs ensures encryption in transit and no internet exposure.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.