A company has a multi-account AWS environment with a central network account and multiple workload accounts. They want to use AWS Transit Gateway to connect VPCs across accounts. The network team has created a Transit Gateway in the network account and shared it using AWS Resource Access Manager (RAM) with the workload accounts. The workload accounts have created VPC attachments to the Transit Gateway. However, traffic is not flowing between the VPCs. The route tables in the workload VPCs have routes pointing to the Transit Gateway. What is the most likely cause?
Attachment alone does not enable routing. The Transit Gateway's route table must contain routes associating each VPC attachment, otherwise packets arriving from one VPC have no path to the other attachments, even though the workload VPC route tables correctly target the gateway.
Why this answer
For traffic to flow between VPCs attached to a Transit Gateway, the Transit Gateway route tables must have routes for the attached VPC CIDRs. When a VPC is attached, a route to the VPC is not automatically added to the Transit Gateway route table unless route propagation is enabled or a static route is created. The most likely cause is that the Transit Gateway route tables lack routes for the attached VPCs, preventing traffic from being forwarded between them.
Exam trap
SAP-C02 often tests the shared responsibility of Transit Gateway routing, and candidates may assume that attaching a VPC automatically adds routes to the Transit Gateway route table, when in fact propagation or static routes are required.
How to eliminate wrong answers
Option A is wrong because route propagation in Transit Gateway route tables is not automatic regardless of account ownership; it must be enabled on the attachment, and cross-account sharing via RAM does not change that. Option C is wrong because security groups could block traffic, but the question states that route tables in the workload VPCs have routes pointing to the Transit Gateway, and the most fundamental issue is the missing Transit Gateway route table routes; security groups are a secondary check. Option D is wrong because VPC flow logs are for logging, not for enabling traffic flow; they have no impact on connectivity.