Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A media company uses AWS Organizations with a central shared services account that hosts a Transit Gateway. Workload accounts in two OUs must be able to route traffic through the Transit Gateway to on-premises networks via AWS Site-to-Site VPN, but must not be able to route traffic to each other. A solutions architect needs to enforce this segmentation centrally. What should the architect do?

⚠ Common exam trap

The trap here is reaching for service control policies to enforce network segmentation, when SCPs control API permissions and cannot filter or block data-plane traffic between attached VPCs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create separate Transit Gateway route tables for each OU, associate the workload VPC attachments with their respective route tables, and only propagate the VPN attachment into both route tables.

Transit Gateway route tables are the correct mechanism for centralized network segmentation. By giving each OU its own route table that propagates only the VPN attachment, workload VPCs can reach on-premises but cannot reach each other. SCPs, Inter-Region peering, and VPC peering with security groups do not provide the required centralized, route-level isolation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply a service control policy to each OU that denies ec2:CreateRoute for routes pointing to the other OU's CIDR ranges.

    Why it's wrong here

    SCPs govern API permissions, not data-plane routing. A principal with existing routes could still send traffic, and SCPs cannot inspect or filter packets. Denying ec2:CreateRoute does not prevent traffic between VPCs that are already attached to the Transit Gateway with propagated routes, so segmentation would not be enforced.

  • ✗

    Enable Transit Gateway Inter-Region Peering between the two OUs and configure static routes to block traffic between them.

    Why it's wrong here

    Inter-Region peering connects Transit Gateways in different Regions and does not provide intra-Region segmentation between OUs. Static routes cannot override propagated routes in a way that reliably blocks traffic, and this design adds complexity without meeting the requirement to isolate the two OUs from each other.

  • ✓

    Create separate Transit Gateway route tables for each OU, associate the workload VPC attachments with their respective route tables, and only propagate the VPN attachment into both route tables.

    Why this is correct

    Transit Gateway route tables control which attachments can reach which destinations. By associating each OU's VPC attachments with a separate route table and propagating only the VPN attachment, traffic can flow to on-premises but not between the OUs. This provides centralized, network-layer segmentation without relying on account-level controls.

  • ✗

    Configure VPC peering between each workload VPC and the shared services VPC, and use security groups to deny traffic between the OUs.

    Why it's wrong here

    VPC peering creates direct connectivity and does not scale well across many accounts. Security groups are stateful and can restrict traffic, but managing them across hundreds of VPCs to enforce OU-level segmentation is fragile. This approach also bypasses the centralized Transit Gateway design and does not use route table isolation.

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.