Skip to content
BytePatterns

SAP-C02 · Domain 1: Design Solutions for Organizational Complexity · 26% of the exam

Task 1.1: Architect network connectivity strategies.

Connecting many VPCs, accounts, Regions and data centers: Transit Gateway and peering, Direct Connect and Site-to-Site VPN, hybrid DNS with Route 53 VPC Resolver, IP address planning, service endpoints, and the tools that show where a packet went.

Study it

  • Connecting many VPCs: Transit Gateway, peering, PrivateLink and shared VPCs

    Partly covered by: VPC: Subnets, NAT & Firewalls

  • Hybrid networks: Direct Connect gateways, Site-to-Site VPN backup and BGP routing

    Partly covered by: Hybrid Networking & DNS

  • Hybrid DNS with Route 53 VPC Resolver endpoints and rules shared across accounts

    Partly covered by: Hybrid Networking & DNS

  • Tracing a flow: VPC Flow Logs, Reachability Analyzer and Network Access Analyzer

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A company has 45 VPCs in 12 accounts of its organization, split between us-east-1 and eu-west-1. Every VPC must be able to reach every other VPC, and the on-premises data center, connected through one AWS Direct Connect connection in us-east-1, must reach the VPCs in both Regions. The network team wants the fewest connections to manage and wants to add VPCs later without touching the existing ones. Which design meets these requirements?

  1. APeer every VPC with every other VPC, and create a private virtual interface from the Direct Connect connection to a virtual private gateway on each VPC
  2. BUse a transit gateway per Region with the local VPCs attached, peer the two, and associate both with one Direct Connect gateway over a transit VIF
  3. CCreate one transit gateway in us-east-1, attach the VPCs of both Regions to it, and connect the Direct Connect connection to it through a transit virtual interface
  4. DAttach a virtual private gateway to each VPC, associate all of them with one Direct Connect gateway, and let the Direct Connect gateway route traffic between the VPCs
Show the answer and why
  • APeer every VPC with every other VPC, and create a private virtual interface from the Direct Connect connection to a virtual private gateway on each VPC

    Incorrect

    VPC peering is one-to-one and not transitive, so 45 VPCs need a full mesh of peering connections, and every new VPC adds a peering connection to each existing VPC. That is the opposite of fewest connections.

  • BUse a transit gateway per Region with the local VPCs attached, peer the two, and associate both with one Direct Connect gateway over a transit VIF

    Correct

    A transit gateway is a Regional router for the VPCs attached to it, and transit gateways in different Regions can be peered. A Direct Connect gateway associated with transit gateways through a transit virtual interface gives on premises a path to their attached VPCs.

  • CCreate one transit gateway in us-east-1, attach the VPCs of both Regions to it, and connect the Direct Connect connection to it through a transit virtual interface

    Incorrect

    A transit gateway acts as a Regional virtual router. VPCs in another Region are connected through a transit gateway in their own Region that is peered with the first one.

  • DAttach a virtual private gateway to each VPC, associate all of them with one Direct Connect gateway, and let the Direct Connect gateway route traffic between the VPCs

    Incorrect

    A Direct Connect gateway does not let the gateways associated with it send traffic to each other, so it cannot provide VPC-to-VPC routing between virtual private gateways.

Many VPCs in several Regions plus a hybrid link is the transit gateway pattern: one transit gateway per Region, peering between them, and a Direct Connect gateway associated with the transit gateways. New VPCs only need an attachment to their Regional transit gateway.

Question 2 · choose 1

A company connects its data center to a shared-services VPC through AWS Direct Connect. Thirty application VPCs in other accounts reach the shared-services VPC through a transit gateway. On-premises servers must resolve records in Route 53 private hosted zones, and instances in every application VPC must resolve names in the on-premises domain corp.example.com, which on-premises DNS servers host. The company wants one central setup with the least ongoing management. What should a solutions architect do?

  1. AConfigure the on-premises DNS servers to forward the AWS zone names to the VPC CIDR +2 address of the shared-services VPC, and set a DHCP options set in each application VPC that points to the on-premises DNS servers
  2. BRun DNS server instances in every application VPC that forward corp.example.com to the on-premises servers and the AWS zones to the VPC resolver
  3. CAssociate the private hosted zones with the on-premises network through the Direct Connect gateway so that on-premises servers query them directly
  4. DCreate Resolver inbound and outbound endpoints in the shared-services VPC, forward corp.example.com through a Resolver rule, and share the rule with the application accounts through AWS RAM
Show the answer and why
  • AConfigure the on-premises DNS servers to forward the AWS zone names to the VPC CIDR +2 address of the shared-services VPC, and set a DHCP options set in each application VPC that points to the on-premises DNS servers

    Incorrect

    AWS documents that forwarding private DNS queries from on-premises DNS servers to a VPC CIDR +2 address is not supported and can give unstable results; a Resolver inbound endpoint is the supported path.

  • BRun DNS server instances in every application VPC that forward corp.example.com to the on-premises servers and the AWS zones to the VPC resolver

    Incorrect

    Self-managed DNS servers in 30 VPCs can be made to work, but they are many servers to patch and keep available. Resolver endpoints and shared rules give the same result as a managed service.

  • CAssociate the private hosted zones with the on-premises network through the Direct Connect gateway so that on-premises servers query them directly

    Incorrect

    Private hosted zones are associated with VPCs. On-premises resolvers reach them by forwarding queries to a Resolver inbound endpoint in a VPC that the zones are associated with.

  • DCreate Resolver inbound and outbound endpoints in the shared-services VPC, forward corp.example.com through a Resolver rule, and share the rule with the application accounts through AWS RAM

    Correct

    On-premises DNS servers forward the AWS zones to the inbound endpoint, and the forwarding rule sends corp.example.com out through the outbound endpoint. Resolver rules can be shared across accounts and associated with each application VPC.

Hybrid DNS in both directions uses an inbound endpoint (on premises to AWS) and an outbound endpoint with forwarding rules (AWS to on premises). Sharing the rules with AWS RAM keeps the endpoints in one VPC for the whole organization.

Question 3 · choose 2

After a network change, application servers in one member account can no longer open TCP connections on port 5432 to an Amazon RDS for PostgreSQL database in another member account. Both VPCs are attached to the same transit gateway. The network team must name the configuration item that blocks the path and must confirm whether the packets reach the database's network interface at all. Which actions should the team take? (Choose TWO.)

  1. ARun a Reachability Analyzer path analysis from the application instance to the database interface, with organization trusted access
  2. BTurn on AWS CloudTrail data events for Amazon RDS and search them for rejected connections from the application subnets
  3. CTurn on RDS Enhanced Monitoring and look for dropped connections in the operating system metrics of the database host instance
  4. DPublish VPC Flow Logs for the database subnet and look for ACCEPT or REJECT records from the application CIDR range on port 5432
  5. ETurn on AWS X-Ray active tracing for the database so that each hop between the two VPCs appears in the trace map
Show the answer and why
  • ARun a Reachability Analyzer path analysis from the application instance to the database interface, with organization trusted access

    Correct

    When the destination is not reachable, Reachability Analyzer names the blocking component, such as a security group, network ACL or route table. With trusted access in Organizations it analyzes paths across accounts.

  • BTurn on AWS CloudTrail data events for Amazon RDS and search them for rejected connections from the application subnets

    Incorrect

    CloudTrail records API activity. A TCP connection to a database port is network traffic, not an API call, so it does not appear in CloudTrail.

  • CTurn on RDS Enhanced Monitoring and look for dropped connections in the operating system metrics of the database host instance

    Incorrect

    Enhanced Monitoring reports operating system metrics such as CPU and memory for the DB instance. It does not show which network component dropped a packet before it reached the instance.

  • DPublish VPC Flow Logs for the database subnet and look for ACCEPT or REJECT records from the application CIDR range on port 5432

    Correct

    Flow log records show the source, destination, port and an ACCEPT or REJECT action for traffic at the network interface, which confirms whether packets arrive and whether they are rejected.

  • ETurn on AWS X-Ray active tracing for the database so that each hop between the two VPCs appears in the trace map

    Incorrect

    X-Ray traces requests through instrumented application code. It does not trace packets through route tables, network ACLs or transit gateways.

Reachability Analyzer explains a path from configuration without sending traffic and names the blocker; flow logs show what actually arrived at the interface. CloudTrail, Enhanced Monitoring and X-Ray look at other layers.

Question 4 · choose 1

A software-as-a-service provider runs a TCP service behind a Network Load Balancer in its own VPC. About 300 customers in their own AWS accounts must reach it privately, without traffic crossing the internet. Many customer VPC CIDR ranges overlap with each other and with the provider's VPC. Customers must be able to start connections to the service, but the provider must not get a network path into customer VPCs. Which solution meets these requirements?

  1. AExpose the Network Load Balancer as a VPC endpoint service and have each allowed customer create an interface VPC endpoint
  2. BShare a transit gateway with the customer accounts through AWS RAM and attach every customer VPC to it with routes to the provider VPC
  3. CCreate a VPC peering connection between the provider VPC and each customer VPC, and add routes only for the load balancer subnets
  4. DAsk each customer to build an AWS Site-to-Site VPN connection from its VPC to a virtual private gateway on the provider VPC
Show the answer and why
  • AExpose the Network Load Balancer as a VPC endpoint service and have each allowed customer create an interface VPC endpoint

    Correct

    With AWS PrivateLink the consumer creates an interface endpoint and starts the connection, the provider allows chosen principals, and the endpoint's network interfaces sit in the consumer VPC, so overlapping address ranges do not conflict.

  • BShare a transit gateway with the customer accounts through AWS RAM and attach every customer VPC to it with routes to the provider VPC

    Incorrect

    A transit gateway routes by destination address, so overlapping CIDR ranges cannot be told apart, and routed attachments give network paths in both directions rather than one-way access to a single service.

  • CCreate a VPC peering connection between the provider VPC and each customer VPC, and add routes only for the load balancer subnets

    Incorrect

    AWS does not allow a VPC peering connection between VPCs with matching or overlapping CIDR blocks, so many of these customers could not peer at all.

  • DAsk each customer to build an AWS Site-to-Site VPN connection from its VPC to a virtual private gateway on the provider VPC

    Incorrect

    VPN connections would still route between overlapping address ranges, and each one gives a routed network path between the two networks, which the provider must avoid.

PrivateLink exposes one service, not a network: the consumer connects to an endpoint inside its own VPC, the provider accepts it, and address overlap does not matter.

Question 5 · choose 1

Twelve teams run microservices on EC2, ECS and Lambda in separate VPCs and accounts. The services call each other over HTTP, and the network team is tired of managing peering, route tables and load balancers for every new pair. Access between services must be authorized. Which approach fits?

  1. AA Site-to-Site VPN connection between every pair of VPCs
  2. BA full mesh of VPC peering connections with security group references
  3. CVPC Lattice with services and client VPCs in one service network
  4. DPublic Application Load Balancers for each service with IP allow lists
Show the answer and why
  • AA Site-to-Site VPN connection between every pair of VPCs

    Incorrect

    VPN connections link networks; they do not simplify service-to-service access or authorization.

  • BA full mesh of VPC peering connections with security group references

    Incorrect

    Peering every pair of VPCs is the routing work the team wants to stop, and peering is not transitive.

  • CVPC Lattice with services and client VPCs in one service network

    Correct

    VPC Lattice connects services across VPCs and accounts, and clients and services in the same service network can communicate if they are authorized to do so.

  • DPublic Application Load Balancers for each service with IP allow lists

    Incorrect

    Exposing internal services publicly and managing IP lists adds risk and work.

Service-to-service connectivity and authorization across VPCs and accounts is what VPC Lattice provides.

Question 6 · choose 1

Sixty VPCs attach to one transit gateway. Production VPCs and development VPCs must not reach each other, but both must reach a shared services VPC and the on-premises network. Which transit gateway design meets this?

  1. ANetwork ACLs in the shared services VPC that block development traffic
  2. BA separate transit gateway for each VPC
  3. CSeparate route tables per environment, propagating only shared services and on-premises routes
  4. DOne default route table for all attachments, with security groups in every VPC to block traffic
Show the answer and why
  • ANetwork ACLs in the shared services VPC that block development traffic

    Incorrect

    Network ACLs in one VPC do not stop production and development VPCs from routing to each other.

  • BA separate transit gateway for each VPC

    Incorrect

    Sixty transit gateways multiply cost and routing work.

  • CSeparate route tables per environment, propagating only shared services and on-premises routes

    Correct

    Attachments are associated with route tables, and routes are propagated from chosen attachments, so each environment learns only the routes it should reach.

  • DOne default route table for all attachments, with security groups in every VPC to block traffic

    Incorrect

    A single route table gives every attachment routes to every other one, leaving isolation to many security groups.

Segmenting traffic on a transit gateway is done with separate route tables, associations and propagations.

Question 7 · choose 1

VPC A is peered with VPC B, and VPC B is peered with VPC C. Instances in VPC A cannot reach instances in VPC C, although route tables in A point the C range at the A-B peering connection. What is the cause?

  1. APeering connections only work between VPCs in the same account
  2. BVPC peering is not transitive, so A needs its own path to C
  3. CThe peering connections need a NAT gateway in VPC B
  4. DThe security groups in VPC C must reference VPC A's security groups
Show the answer and why
  • APeering connections only work between VPCs in the same account

    Incorrect

    Peering works between VPCs in different accounts and Regions too.

  • BVPC peering is not transitive, so A needs its own path to C

    Correct

    Transitive peering relationships are not supported; a VPC has no peering relationship with VPCs it is not directly peered with.

  • CThe peering connections need a NAT gateway in VPC B

    Incorrect

    Peered traffic does not pass through a NAT gateway in a middle VPC.

  • DThe security groups in VPC C must reference VPC A's security groups

    Incorrect

    Security groups cannot fix the missing routing path between A and C.

VPC peering is one-to-one and never transitive.

Question 8 · choose 1

A dual-stack VPC hosts back-end servers that must download updates over IPv6 from the internet. Nothing on the internet may start IPv6 connections to these servers. Which component meets this requirement for IPv6 traffic?

  1. AA virtual private gateway
  2. BAn egress-only internet gateway with a route for ::/0
  3. CAn internet gateway with a route for ::/0 in the private route table
  4. DA NAT gateway in a public subnet
Show the answer and why
  • AA virtual private gateway

    Incorrect

    A virtual private gateway connects to VPNs, not to the internet.

  • BAn egress-only internet gateway with a route for ::/0

    Correct

    An egress-only internet gateway allows outbound IPv6 traffic and prevents the internet from starting IPv6 connections to instances.

  • CAn internet gateway with a route for ::/0 in the private route table

    Incorrect

    An internet gateway alone lets the internet start connections to instances with public IPv6 addresses.

  • DA NAT gateway in a public subnet

    Incorrect

    NAT gateways are the outbound-only option for IPv4 traffic.

Outbound-only IPv6 internet access uses an egress-only internet gateway.

Question 9 · choose 2

A security team must inspect all traffic entering and leaving several VPCs with a third-party firewall product that runs on EC2. The firewalls must scale and stay highly available, and traffic must be steered to them transparently. Which steps meet these requirements? (Choose TWO.)

  1. ATurn on VPC Flow Logs and have the firewall read them
  2. BRun one large firewall instance per VPC with an Elastic IP address
  3. CPut the firewall instances behind an Application Load Balancer
  4. DRegister the firewall instances in a target group of a Gateway Load Balancer
  5. ERoute the VPC traffic through Gateway Load Balancer endpoints in the route tables
Show the answer and why
  • ATurn on VPC Flow Logs and have the firewall read them

    Incorrect

    Flow logs record traffic metadata after the fact; they do not send packets through a firewall.

  • BRun one large firewall instance per VPC with an Elastic IP address

    Incorrect

    A single instance per VPC is neither scalable nor highly available.

  • CPut the firewall instances behind an Application Load Balancer

    Incorrect

    An Application Load Balancer handles HTTP requests, not transparent inspection of all network traffic.

  • DRegister the firewall instances in a target group of a Gateway Load Balancer

    Correct

    Gateway Load Balancers deploy, scale and manage virtual appliances such as firewalls.

  • ERoute the VPC traffic through Gateway Load Balancer endpoints in the route tables

    Correct

    Gateway Load Balancer endpoints are VPC endpoints that carry traffic between application VPCs and the appliances across VPC boundaries.

Third-party inspection appliances scale behind a Gateway Load Balancer and receive traffic through its endpoints.

Practise domain 1 →Practise all domains →