nerdexam
Amazon

SOA-C03 · Question #172

A company has two AWS accounts connected by a transit gateway. Each account has one VPC in the same AWS Region. The company wants to simplify inbound and outbound rules in security groups by referenci

The correct answer is C. Enable security group referencing support on each transit gateway attachment.. AWS Transit Gateway supports security group referencing across VPCs, but this feature must be explicitly enabled on each transit gateway attachment. Once enabled, security groups in one VPC can reference security groups in another VPC attached to the same transit gateway, simplif

Submitted by jakub_pl· Mar 5, 2026Networking

Question

A company has two AWS accounts connected by a transit gateway. Each account has one VPC in the same AWS Region. The company wants to simplify inbound and outbound rules in security groups by referencing security group IDs instead of IP CIDR blocks. Which solution will meet this requirement?

Options

  • ACreate VPC peering connections and remove the transit gateway.
  • BEnable security group referencing support on the transit gateway.
  • CEnable security group referencing support on each transit gateway attachment.
  • DDeploy private NAT gateways in each VPC.

How the community answered

(22 responses)
  • A
    9% (2)
  • B
    5% (1)
  • C
    86% (19)

Explanation

AWS Transit Gateway supports security group referencing across VPCs, but this feature must be explicitly enabled on each transit gateway attachment. Once enabled, security groups in one VPC can reference security groups in another VPC attached to the same transit gateway, simplifying rule management and improving security posture. Enabling the feature on the transit gateway itself is not sufficient; it must be enabled per attachment to allow traffic evaluation based on security group IDs. This approach avoids brittle CIDR-based rules and allows dynamic scaling without rule updates. Option A removes the transit gateway, which contradicts the existing architecture. Option B is incomplete. Option D does not address security group referencing. Thus, enabling security group referencing on each transit gateway attachment is the correct Exam Questions, Study Guides, Practice Tests. Lead the way to help you pass any IT Certification exams, 100% Pass Guaranteed or Full Refund. Especially Cisco, Microsoft, CompTIA, Citrix, EMC, HP, Oracle, VMware, Juniper, Check Point, LPI, Nortel, EXIN and so on. Our Slogan: First Test, First Pass. Help you to pass any IT Certification exams at the first try. You can reach us at any of the email addresses listed below. Any problems about IT certification or our products, you could rely upon us, we will give you satisfactory answers in 24 hours.

Topics

#transit gateway#security group referencing#cross-account networking#TGW attachments

Community Discussion

No community discussion yet for this question.

Full SOA-C03 Practice