nerdexam
Amazon

SAP-C02 · Question #814

A company uses AWS Organizations. The company creates a central VPC in an AWS account that is designated for networking in a single AWS Region. The central VPC has an AWS Site-to- Site VPN connection

The correct answer is B. Use AWS Resource Access Manager to share the VPN connection in the central VPC with the. Using AWS Resource Access Manager (RAM) to share the VPN connection in the central VPC with the new AWS account is the most cost-effective solution. By sharing the existing VPN connection, the new account can use the same VPN tunnel, eliminating the need for a new Site- to-Site V

Submitted by valeria.br· Mar 6, 2026Design Solutions for Organizational Complexity

Question

A company uses AWS Organizations. The company creates a central VPC in an AWS account that is designated for networking in a single AWS Region. The central VPC has an AWS Site-to- Site VPN connection to the company's on-premises network. A solutions architect must create another AWS account that uses the same networking resources that the central VPC uses. Which solution meets these requirements MOST cost-effectively?

Options

  • ACreate a VPC in the new AWS account. Create a new Site-to-Site VPN connection for the on-
  • BUse AWS Resource Access Manager to share the VPN connection in the central VPC with the
  • CCreate a VPC in the new AWS account. Configure a virtual private gateway to connect to the
  • DUse AWS Resource Access Manager to share the subnets in the central VPC with the new AWS

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    72% (28)
  • C
    8% (3)
  • D
    15% (6)

Explanation

Using AWS Resource Access Manager (RAM) to share the VPN connection in the central VPC with the new AWS account is the most cost-effective solution. By sharing the existing VPN connection, the new account can use the same VPN tunnel, eliminating the need for a new Site- to-Site VPN connection. This approach reduces the cost of maintaining separate VPN connections for each account while still allowing the new AWS account to use the shared networking resources in the central VPC.

Community Discussion

No community discussion yet for this question.

Full SAP-C02 Practice