For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 7Question 56
    Hard1 markMultiple Choice
    Domain 1.1: Network ConnectivityNetworkingTransit GatewaySecurity

    AWS SAP-C02 · Question 56 · Domain 1.1: Network Connectivity

    An enterprise is building a centralized network inspection architecture using AWS Transit Gateway. They have a dedicated Inspection VPC containing AWS Network Firewall. They want to ensure that traffic between any two application VPCs is routed through the Inspection VPC. How should the Transit Gateway route tables be configured?

    Answer options:

    A.

    Use a single TGW route table and enable appliance mode on all VPC attachments.

    B.

    Create two TGW route tables. Associate application VPCs with a route table that routes all traffic to the Inspection VPC. Associate the Inspection VPC with a route table that has routes to all application VPCs.

    C.

    Configure VPC peering between all application VPCs and the Inspection VPC.

    D.

    Enable AWS Shield Advanced on the Transit Gateway.

    How to approach this question

    Understand Transit Gateway route table isolation.

    Full Answer

    B.Create two TGW route tables. Associate application VPCs with a route table that routes all traffic to the Inspection VPC. Associate the Inspection VPC with a route table that has routes to all application VPCs.✓ Correct
    To route traffic through a central inspection VPC, you need at least two Transit Gateway route tables. One for the spoke VPCs (routing everything to the inspection VPC) and one for the inspection VPC (routing traffic to its final destination).

    Common mistakes

    Trying to use a single route table, which creates a loop.
    Question 55All questionsQuestion 57

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 7

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A global enterprise is designing a multi-region network architecture connecting 50 AWS accounts a...HardQ02A company is migrating its hybrid network to AWS. They have two 10 Gbps AWS Direct Connect connec...HardQ03An enterprise has 100 AWS accounts in AWS Organizations. The security team mandates that all Amaz...MediumQ04A financial company requires that all EBS volumes, S3 buckets, and RDS databases be encrypted usi...EasyQ05An enterprise is designing a disaster recovery strategy for a critical application running on Ama...Hard
    View all 75 questions →