SOA-C02 Networking and Content Delivery Practice Question
A company has multiple VPCs in the same AWS account and Region, each with overlapping CIDR blocks (10.0.0.0/16). The SysOps administrator needs to establish connectivity between all VPCs and the on-premises network via AWS Transit Gateway. Additionally, certain VPCs must be isolated from each other while still reaching on-premises. How should the administrator configure the Transit Gateway to meet these requirements?
⚠ Common exam trap
Candidates often assume a single Transit Gateway route table is sufficient for all VPCs, overlooking the need for isolation between specific VPC groups when overlapping CIDRs are present.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create multiple Transit Gateway route tables: one for each group of VPCs that need to communicate, and associate each VPC attachment with the appropriate route table. Add static routes to the on-premises network in each route table.
AWS Transit Gateway supports multiple route tables, allowing you to isolate VPC attachments from each other while still providing a common route to the on-premises network. By creating separate route tables for each group of VPCs that need to communicate, and associating the appropriate VPC attachments with those tables, you can enforce isolation between groups. Adding static routes to the on-premises network in each route table ensures all VPCs can reach on-premises, even when they cannot communicate with each other.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a single Transit Gateway route table and add routes for all VPCs and the on-premises network.
Why it's wrong here
A single Transit Gateway route table forces every VPC attachment and the on-premises attachment into one shared routing domain. With overlapping CIDRs, the TGW cannot uniquely resolve destinations because multiple VPC attachments advertise the same prefix, creating ambiguous next hops and unpredictable routing. Additionally, all VPCs would be able to route to each other, violating the isolation requirement. This design also propagates on-premises routes identically to all VPCs, but the fundamental flaw is that overlapping prefixes cannot coexist in one table.
- ✓
Create multiple Transit Gateway route tables: one for each group of VPCs that need to communicate, and associate each VPC attachment with the appropriate route table. Add static routes to the on-premises network in each route table.
Why this is correct
Create separate Transit Gateway route tables, one per group of VPCs that must communicate, and associate each VPC attachment with its group's route table. Within each route table, add static routes pointing to the on-premises network (or propagate from the VPN/DX attachment) so every group retains reachability to the data center. Because route tables are independent, overlapping CIDRs across groups are never compared, avoiding routing conflicts; traffic between groups is denied by default since no routes exist. This gives you transitive routing within a group and full isolation between groups, which is exactly what the scenario demands.
- ✗
Use VPC peering instead of Transit Gateway to connect VPCs, and use Direct Connect Gateway for on-premises connectivity.
Why it's wrong here
VPC peering does not support overlapping CIDR ranges—you cannot create a peering connection between VPCs whose CIDRs overlap, so the core requirement is impossible. Peering is also non-transitive, meaning you would need a mesh of connections, and it does not offer a hub-and-spoke model with route-table isolation. Adding a Direct Connect Gateway only manages DX-based connectivity to on-premises; it does not provide inter-VPC routing or segmentation. Thus this combined approach fails on both overlapping CIDRs and isolation.
- ✗
Configure VPN connections between each VPC and the on-premises network, bypassing Transit Gateway.
Why it's wrong here
Establishing individual VPN connections from each VPC to the on-premises network creates a set of point-to-point links that do not enable inter-VPC communication; VPCs would still be isolated from one another unless you also add separate peering or routing. Overlapping CIDRs remain problematic because on-premises routers cannot distinguish identical prefixes from different VPCs, and each VPN tunnel would carry conflicting routes. This approach adds operational complexity and per-VPN cost without delivering the centrally managed, isolated hub-and-spoke architecture that Transit Gateway provides. It also leaves the requirement for isolated communication groups entirely unaddressed.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.