Multi-Region Active Directory Authentication with AWS Managed Microsoft AD and AD Connector
A multinational corporation is migrating its on-premises Active Directory (AD) to AWS Managed Microsoft AD. The company has a hub-and-spoke VPC topology with a central transit gateway. The AD domain controllers must be deployed in two different AWS Regions for disaster recovery. The corporate security policy requires that all AD traffic between Regions must traverse the transit gateway and be inspected by a third-party firewall appliance deployed in the inspection VPC. Which architecture meets these requirements?
⚠ Common exam trap
The trap is that candidates may think you can attach VPCs from different Regions to a single transit gateway, but in reality, transit gateway attachments are regional. Cross-Region connectivity requires transit gateway peering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy AD in two Regions, attach both VPCs to the transit gateway, and enable cross-Region transit gateway peering. Use route tables to direct AD traffic through the inspection VPC.
It uses cross-Region transit gateway peering, which allows VPCs in different Regions to communicate through their respective transit gateways. By attaching both VPCs to their local transit gateways and peering those gateways, you can configure route tables to force AD traffic through the inspection VPC in one Region, satisfying the firewall inspection requirement. Option D is incorrect because you cannot attach a VPC in a secondary Region to a transit gateway in the primary Region; transit gateway attachments are regional.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy AD in two Regions and use a VPN connection between the VPCs to replicate data.
Why it's wrong here
Incorrect. VPN connections between VPCs do not require a transit gateway and do not integrate with a central inspection VPC.
- ✗
Deploy a single AD domain in one Region and use AD replication over a VPC peering connection to a second Region.
Why it's wrong here
Incorrect. VPC peering does not support transitive routing through an inspection VPC, and cross-Region peering alone cannot enforce firewall inspection.
- ✓
Deploy AD in two Regions, attach both VPCs to the transit gateway, and enable cross-Region transit gateway peering. Use route tables to direct AD traffic through the inspection VPC.
Why this is correct
Cross-Region transit gateway peering carries AD replication traffic between the two Regional directories, while transit gateway route tables in each Region force that traffic through the inspection VPC attachment, satisfying the security policy's inspection mandate. AWS Managed Microsoft AD domain controllers stay Regional, so DR is met without exposing replication to the public internet.
- ✗
Deploy AD in two Regions, attach both VPCs to a transit gateway in the primary Region, and use a transit gateway inter-Region peering attachment. Configure route tables to force traffic through the inspection VPC in the primary Region.
Why it's wrong here
Incorrect. VPCs in different Regions cannot be attached to the same transit gateway; transit gateway attachments are regional. This architecture is not feasible.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.