For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 2Question 12
    Hard1 markMultiple Choice
    Domain 1.1: Network ConnectivityTransit GatewayNetwork FirewallRouting

    AWS SAP-C02 · Question 12 · Domain 1.1: Network Connectivity

    An enterprise is implementing a centralized egress architecture using AWS Network Firewall. They have a Transit Gateway connecting multiple spoke VPCs to a central Security VPC. Which TWO routing configurations are required to ensure all internet-bound traffic from spoke VPCs is inspected by the Network Firewall? (Select TWO)

    Answer options:

    A.

    In the spoke VPCs, set the default route (0.0.0.0/0) to point to the Internet Gateway.

    B.

    In the spoke VPCs, set the default route (0.0.0.0/0) to point to the Transit Gateway attachment.

    C.

    In the Transit Gateway route table, set the default route to point to the spoke VPC attachments.

    D.

    In the Security VPC, set the default route in the public subnet to point to the Transit Gateway.

    E.

    In the Transit Gateway route table associated with the spoke VPCs, set the default route (0.0.0.0/0) to point to the Security VPC attachment.

    F.

    Configure VPC Peering between all spoke VPCs and the Security VPC.

    How to approach this question

    Trace the packet path from Spoke -> TGW -> Security VPC.

    Full Answer

    To centralize egress, spoke VPCs must route 0.0.0.0/0 to the TGW. The TGW route table associated with the spokes must then route 0.0.0.0/0 to the Security VPC attachment.

    Common mistakes

    Misconfiguring the TGW route tables.
    Question 11All questionsQuestion 13

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 2

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A company is setting up a multi-account AWS environment using AWS Organizations. They need to ens...EasyQ02An enterprise needs to connect its on-premises data center to AWS. They require a dedicated, priv...EasyQ03A company wants to share a single AWS Transit Gateway across multiple AWS accounts within their A...EasyQ04An architect needs to design a highly available database architecture that spans multiple AWS Reg...EasyQ05A global financial institution is migrating its core banking application to AWS. The application ...Medium
    View all 75 questions →