For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 7Question 01
    Hard1 markMultiple Choice
    Domain 1.1: Network ConnectivityNetworkingTransit GatewayDirect Connect

    AWS SAP-C02 · Question 01 · Domain 1.1: Network Connectivity

    A global enterprise is designing a multi-region network architecture connecting 50 AWS accounts across 3 AWS Regions and 4 on-premises data centers. The company requires transitive routing between all VPCs and on-premises networks. Traffic between AWS Regions must be encrypted and traverse the AWS global network. The solution must minimize operational overhead and support up to 50 Gbps of bandwidth per region. Which architecture meets these requirements MOST cost-effectively?

    Answer options:

    A.

    Deploy AWS Transit Gateway in each Region. Peer the Transit Gateways. Connect on-premises data centers using AWS Direct Connect with MACsec.

    B.

    Create a full mesh of VPC peering connections across all 50 accounts and 3 Regions. Use AWS VPN CloudHub for on-premises connectivity.

    C.

    Deploy a third-party SD-WAN virtual appliance in a transit VPC in each Region. Establish IPsec VPNs between all VPCs and the transit VPCs.

    D.

    Use AWS Direct Connect Gateway to connect all VPCs directly to the on-premises networks. Enable SiteLink for VPC-to-VPC routing.

    How to approach this question

    Identify the requirement for transitive routing and inter-region connectivity over the AWS backbone.

    Full Answer

    A.Deploy AWS Transit Gateway in each Region. Peer the Transit Gateways. Connect on-premises data centers using AWS Direct Connect with MACsec.✓ Correct
    AWS Transit Gateway acts as a regional virtual router. Peering them across regions allows traffic to stay on the AWS global network and is encrypted by default.

    Common mistakes

    Selecting VPC peering, which lacks transitive routing capabilities.
    All questionsQuestion 02

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 7

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q02A company is migrating its hybrid network to AWS. They have two 10 Gbps AWS Direct Connect connec...HardQ03An enterprise has 100 AWS accounts in AWS Organizations. The security team mandates that all Amaz...MediumQ04A financial company requires that all EBS volumes, S3 buckets, and RDS databases be encrypted usi...EasyQ05An enterprise is designing a disaster recovery strategy for a critical application running on Ama...HardQ06A company is setting up a multi-account AWS environment using AWS Control Tower. They need to ens...Medium
    View all 75 questions →