Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A large enterprise is migrating to AWS and wants to implement a multi-account strategy with centralized network connectivity. The company has multiple VPCs in various accounts that need to communicate with each other and with on-premises resources. The solution must be scalable and minimize operational overhead. Which design should be used?

⚠ Common exam trap

Many exam-takers confuse AWS PrivateLink (which is for service-to-service communication) with a hub-and-spoke solution, or assume VPC peering can scale linearly, ignoring the lack of transitive routing and the operational burden of managing a full mesh.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an AWS Transit Gateway in a central network account and attach all VPCs from the various accounts.

AWS Transit Gateway acts as a central hub for interconnecting VPCs and on-premises networks, enabling scalable, low-operational-overhead connectivity across multiple accounts. By placing the Transit Gateway in a central network account and using AWS Resource Access Manager to share it with other accounts, the enterprise can avoid the complexity of managing many individual connections while supporting transitive routing and centralized control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS PrivateLink to connect VPCs via interface endpoints.

    Why it's wrong here

    PrivateLink provides one-way access to specific services via interface endpoints; it does not deliver transitive VPC-to-VPC routing or on-premises connectivity. It tempts because it privately exposes services across accounts, which suits consuming a shared service, not building a scalable any-to-any network fabric with hybrid access.

  • ✗

    Create a VPC peering connection between each pair of VPCs that need to communicate.

    Why it's wrong here

    Full-mesh peering requires a connection per VPC pair, and peering is non-transitive, so it cannot reach on-premises or scale across many accounts. It tempts because peering privately links two VPCs simply, which suits a small, fixed number of VPCs, not an enterprise multi-account topology.

  • ✗

    Set up a VPN connection from each VPC to the on-premises network and use routing to enable inter-VPC communication.

    Why it's wrong here

    Per-VPC VPNs terminate separate tunnels to on-premises and cannot route traffic between VPCs without additional transit infrastructure, multiplying operational overhead. It tempts because VPNs do connect VPCs to on-premises, which is correct for a single VPC, but not for many accounts needing centralised, scalable inter-VPC routing.

  • ✓

    Use an AWS Transit Gateway in a central network account and attach all VPCs from the various accounts.

    Why this is correct

    A central Transit Gateway in a network account lets VPCs from many accounts attach as spokes, providing scalable transitive routing to each other and to on-premises via VPN or Direct Connect, with far less operational overhead than per-VPC peering meshes.

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.