SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A media company uses AWS Organizations with a central shared services account that hosts a Transit Gateway. Workload accounts in two OUs must be able to route traffic through the Transit Gateway to on-premises networks via AWS Site-to-Site VPN, but must not be able to route traffic to each other. A solutions architect needs to enforce this segmentation centrally. What should the architect do?
⚠ Common exam trap
The trap here is reaching for service control policies to enforce network segmentation, when SCPs control API permissions and cannot filter or block data-plane traffic between attached VPCs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create separate Transit Gateway route tables for each OU, associate the workload VPC attachments with their respective route tables, and only propagate the VPN attachment into both route tables.
Transit Gateway route tables are the correct mechanism for centralized network segmentation. By giving each OU its own route table that propagates only the VPN attachment, workload VPCs can reach on-premises but cannot reach each other. SCPs, Inter-Region peering, and VPC peering with security groups do not provide the required centralized, route-level isolation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply a service control policy to each OU that denies ec2:CreateRoute for routes pointing to the other OU's CIDR ranges.
Why it's wrong here
SCPs govern API permissions, not data-plane routing. A principal with existing routes could still send traffic, and SCPs cannot inspect or filter packets. Denying ec2:CreateRoute does not prevent traffic between VPCs that are already attached to the Transit Gateway with propagated routes, so segmentation would not be enforced.
- ✗
Enable Transit Gateway Inter-Region Peering between the two OUs and configure static routes to block traffic between them.
Why it's wrong here
Inter-Region peering connects Transit Gateways in different Regions and does not provide intra-Region segmentation between OUs. Static routes cannot override propagated routes in a way that reliably blocks traffic, and this design adds complexity without meeting the requirement to isolate the two OUs from each other.
- ✓
Create separate Transit Gateway route tables for each OU, associate the workload VPC attachments with their respective route tables, and only propagate the VPN attachment into both route tables.
Why this is correct
Transit Gateway route tables control which attachments can reach which destinations. By associating each OU's VPC attachments with a separate route table and propagating only the VPN attachment, traffic can flow to on-premises but not between the OUs. This provides centralized, network-layer segmentation without relying on account-level controls.
- ✗
Configure VPC peering between each workload VPC and the shared services VPC, and use security groups to deny traffic between the OUs.
Why it's wrong here
VPC peering creates direct connectivity and does not scale well across many accounts. Security groups are stateful and can restrict traffic, but managing them across hundreds of VPCs to enforce OU-level segmentation is fragile. This approach also bypasses the centralized Transit Gateway design and does not use route table isolation.
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.