SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A multinational company has a multi-account AWS environment with a central network account. They use AWS Transit Gateway to connect all VPCs. The company wants to implement centralized inspection of all traffic between VPCs using a third-party firewall appliance running on EC2 instances in a dedicated inspection VPC. Traffic must be inspected without modifying workload VPC route tables when new VPCs are added. What should the solutions architect recommend?
⚠ Common exam trap
The trap here is thinking that VPC peering or PrivateLink can provide centralized inspection without modifying workload VPC route tables, when they actually require per-VPC route changes or do not support arbitrary traffic inspection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Transit Gateway with a separate route table for the inspection VPC, and configure the firewall instances as appliances in the inspection VPC. Use Transit Gateway route table associations and propagations to direct traffic through the inspection VPC.
Transit Gateway route tables allow centralized traffic steering. By associating workload VPC attachments with a route table that routes to the inspection VPC, and the inspection VPC attachment with a route table that routes back, traffic is forced through the firewall. New VPCs only need to be associated with the correct route table, avoiding workload VPC route table changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy the firewall instances in the central network account and use AWS Resource Access Manager to share them with all workload accounts, then update each workload VPC's route tables to point to the firewall ENIs.
Why it's wrong here
Sharing ENIs via RAM is not supported for this use case, and updating each workload VPC's route tables violates the requirement. This approach also does not provide a scalable, centralized solution for adding new VPCs without manual route table changes.
- ✗
Use AWS PrivateLink to connect each workload VPC to the inspection VPC, and configure endpoint policies to redirect traffic.
Why it's wrong here
AWS PrivateLink is designed for private connectivity to services, not for inspecting all inter-VPC traffic. It does not support transitive routing or inspection of arbitrary traffic between VPCs. Endpoint policies control access to the service, not traffic redirection, so this approach fails to meet the inspection requirement.
- ✓
Use AWS Transit Gateway with a separate route table for the inspection VPC, and configure the firewall instances as appliances in the inspection VPC. Use Transit Gateway route table associations and propagations to direct traffic through the inspection VPC.
Why this is correct
Transit Gateway route tables can be used to isolate and direct traffic. By associating workload VPC attachments with a route table that points to the inspection VPC attachment, and associating the inspection VPC attachment with a route table that points to workload VPCs, you can force traffic through the firewall without modifying workload VPC route tables. New VPCs can be associated with the appropriate route table centrally.
- ✗
Create a VPC peering connection between each workload VPC and the inspection VPC, and update each workload VPC's route tables to point to the inspection VPC for inter-VPC traffic.
Why it's wrong here
VPC peering requires modifying route tables in each workload VPC, which contradicts the requirement to avoid changing workload VPC route tables when new VPCs are added. It also does not scale well and lacks the centralized control provided by Transit Gateway route tables.
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.