Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A media company has 200 AWS accounts in AWS Organizations. The networking team wants to provide each account with a shared VPC subnet from a central networking account. The central networking account owns the VPC and subnets. Workload accounts must be able to launch resources into the shared subnets, but they must not be able to modify the subnet configuration or delete the shared subnets. Which solution meets these requirements?

⚠ Common exam trap

The trap here is assuming VPC peering or Transit Gateway grants subnet usage, when only AWS RAM shares subnets and only a service control policy prevents modification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Resource Access Manager to share the subnets from the networking account to the organization, and attach a service control policy to workload accounts denying ec2:ModifySubnetAttribute and ec2:DeleteSubnet.

Sharing subnets from a central VPC is done with AWS Resource Access Manager, which lets participant accounts launch resources into shared subnets while the owner retains control. To prevent participants from modifying or deleting the shared subnets, a service control policy denies the relevant EC2 subnet actions. Together these meet the requirements for shared use with owner-controlled configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a VPC peering connection from each workload VPC to the central VPC, and grant each workload account IAM permissions to create subnets in the central VPC.

    Why it's wrong here

    VPC peering connects VPCs for routing but does not allow an account to launch resources into another account's subnets. IAM permissions in the workload account cannot grant access to subnets owned by the central account. This approach does not provide shared subnet usage and would not prevent modification of the central subnets, so it fails the requirement.

  • ✗

    Use AWS Transit Gateway to attach each workload VPC to the central VPC, and create a route table entry that allows workloads to use the central subnets.

    Why it's wrong here

    A Transit Gateway provides routing between VPCs but does not share subnets. Workload accounts cannot launch instances into the central account's subnets through a TGW attachment; the instances remain in their own VPCs. This does not satisfy the requirement to use shared subnets and does not address preventing subnet modification or deletion.

  • ✗

    Create an AWS Direct Connect connection between each workload account and the central networking account, and configure a private virtual interface for subnet access.

    Why it's wrong here

    Direct Connect is a physical network connection for hybrid connectivity, not a mechanism for sharing subnets between AWS accounts. It cannot grant an account the ability to launch resources into another account's VPC subnets. This solution is unrelated to the requirement and would add cost and complexity without providing shared subnet functionality.

  • ✓

    Use AWS Resource Access Manager to share the subnets from the networking account to the organization, and attach a service control policy to workload accounts denying ec2:ModifySubnetAttribute and ec2:DeleteSubnet.

    Why this is correct

    AWS RAM is the supported way to share VPC subnets across accounts in an organization. The participant accounts can launch resources into shared subnets but do not own the subnet. Adding a service control policy that denies subnet modification and deletion actions enforces the restriction that workload accounts cannot alter or remove the shared subnets, meeting both requirements.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.