Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A multinational company has a multi-account AWS environment with a central network account. They use AWS Transit Gateway to connect all VPCs. The company wants to implement centralized inspection of all traffic between VPCs using a third-party firewall appliance running on EC2 instances in a dedicated inspection VPC. Traffic must be inspected without modifying workload VPC route tables when new VPCs are added. What should the solutions architect recommend?

⚠ Common exam trap

The trap here is thinking that VPC peering or PrivateLink can provide centralized inspection without modifying workload VPC route tables, when they actually require per-VPC route changes or do not support arbitrary traffic inspection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Transit Gateway with a separate route table for the inspection VPC, and configure the firewall instances as appliances in the inspection VPC. Use Transit Gateway route table associations and propagations to direct traffic through the inspection VPC.

Transit Gateway route tables allow centralized traffic steering. By associating workload VPC attachments with a route table that routes to the inspection VPC, and the inspection VPC attachment with a route table that routes back, traffic is forced through the firewall. New VPCs only need to be associated with the correct route table, avoiding workload VPC route table changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy the firewall instances in the central network account and use AWS Resource Access Manager to share them with all workload accounts, then update each workload VPC's route tables to point to the firewall ENIs.

    Why it's wrong here

    Sharing ENIs via RAM is not supported for this use case, and updating each workload VPC's route tables violates the requirement. This approach also does not provide a scalable, centralized solution for adding new VPCs without manual route table changes.

  • ✗

    Use AWS PrivateLink to connect each workload VPC to the inspection VPC, and configure endpoint policies to redirect traffic.

    Why it's wrong here

    AWS PrivateLink is designed for private connectivity to services, not for inspecting all inter-VPC traffic. It does not support transitive routing or inspection of arbitrary traffic between VPCs. Endpoint policies control access to the service, not traffic redirection, so this approach fails to meet the inspection requirement.

  • ✓

    Use AWS Transit Gateway with a separate route table for the inspection VPC, and configure the firewall instances as appliances in the inspection VPC. Use Transit Gateway route table associations and propagations to direct traffic through the inspection VPC.

    Why this is correct

    Transit Gateway route tables can be used to isolate and direct traffic. By associating workload VPC attachments with a route table that points to the inspection VPC attachment, and associating the inspection VPC attachment with a route table that points to workload VPCs, you can force traffic through the firewall without modifying workload VPC route tables. New VPCs can be associated with the appropriate route table centrally.

  • ✗

    Create a VPC peering connection between each workload VPC and the inspection VPC, and update each workload VPC's route tables to point to the inspection VPC for inter-VPC traffic.

    Why it's wrong here

    VPC peering requires modifying route tables in each workload VPC, which contradicts the requirement to avoid changing workload VPC route tables when new VPCs are added. It also does not scale well and lacks the centralized control provided by Transit Gateway route tables.

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.