Share a Transit Gateway with AWS RAM for a self-service cross-account connection

Answer Correct answer: B — Share the shared services transit gateway through AWS RAM with auto acceptance, then attach it from the development account as needed.

A company uses an organization in AWS Organizations to manage multiple AWS accounts. The company hosts some applications in a VPC in the company's shared services account. The company has attached a transit gateway to the VPC in the shared services account. The company is developing a new capability and has created a development environment that requires access to the applications that are in the shared services account. The company intends to delete and recreate resources frequently in the development account. The company also wants to give a development team the ability to recreate the team's connection to the shared services account as required. Which solution will meet these requirements?

  1. Create a transit gateway in the development account. Create a transit gateway peering request to the shared services account. Configure the shared services transit gateway to automatically accept peering connections.
  2. Turn on automatic acceptance for the transit gateway in the shared services account. Use AWS Resource Access Manager (AWS RAM) to share the transit gateway resource in the shared services account with the development account. Accept the resource in the development account. Create a transit gateway attachment in the development account. Correct Answer
  3. Turn on automatic acceptance for the transit gateway in the shared services account. Create a VPC endpoint. Use the endpoint policy to grant permissions on the VPC endpoint for the development account. Configure the endpoint service to automatically accept connection requests. Provide the endpoint details to the development team.
  4. Create an Amazon EventBridge rule to invoke an AWS Lambda function that accepts the transit gateway attachment when the development account makes an attachment request. Use AWS Network Manager to share the transit gateway in the shared services account with the development account. Accept the transit gateway in the development account.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

AWS RAM shares the existing transit gateway rather than creating a new one, so the development team creates and deletes its own attachments on the shared gateway without any cross-account request workflow.

A development account needs access to applications in a shared services VPC that is attached to a transit gateway. Resources in the development account are created and destroyed frequently, and the team must be able to re-establish its own connection on demand.

Creating a second transit gateway in the development account and peering the two. That adds a gateway and a peering relationship to manage, and the connection cannot be re-established by the development team alone because peering acceptance lives in the other account.

Community Discussion (7 comments)

AzureDP900 👍 2
Option B uses AWS Resource Access Manager (RAM) to share the transit gateway resource with the development account. This eliminates the need for manual peering requests and allows the development team to access the shared services account without requiring intervention on both sides. The use of RAM also simplifies the process of granting permissions and managing resources, making it a suitable solution for this use case. Option B is more straightforward and easier to implement than Option C, which involves creating a VPC endpoint and configuring an endpoint service.
dman 👍 1 Selected: A
The dev account has frequent changes and needs to connect with the ShareServices account hence connection request is from Dev -> SS
trungtd 👍 3 Selected: B
A is incorrect: creating and managing another transit gateway in the development account and setting up peering. This adds unnecessary complexity and management overhead. B is correct: the development account can create transit gateway attachments without needing manual intervention every time an attachment is made. C is incorrect: Not usecase of VPC endpoints. VPC endpoints are typically used for connecting to AWS services privately without traversing the public internet. This option does not align well with the requirement to access applications in a VPC through a transit gateway. D is incorrect: too complicated
titi_r 👍 2 Selected: B
"B" is correct. "C" is wrong: Endpoint services require either a Network Load Balancer or a Gateway Load Balancer., However, the answer does not mention the creation of a NLB. https://docs.aws.amazon.com/vpc/latest/privatelink/create-endpoint-service.html
pangchn 👍 3 Selected: B
B Auto accept shared attachments https://docs.aws.amazon.com/vpc/latest/tgw/tgw-transit-gateways.html Then, create create TGW attachment in dev account
Dgix 👍 3 Selected: B
B is correct. A is wrong becase TGW peering is done between regions, not accounts. C is rubbish D is overengineered and weird, using Network Manager for sharing the TGW rather than RAM which is best practice.
CMMC 👍 2 Selected: B
Provide the flexibility needed for the development team to recreate their connection to the shared services account

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS RAM can share a transit gateway with another account, and automatic acceptance makes the resource share available without a manual accept step in the shared account. The development team then creates its own transit gateway attachment whenever it needs connectivity and deletes it when the environment is torn down, which is exactly the self-service requirement.

Why the Other Options Are Wrong

A: Creating a transit gateway in the development account and peering it adds an extra gateway plus a peering relationship to maintain, and it does not give the development team on-demand control over the connection. C: A VPC endpoint service requires a Network Load Balancer or a Gateway Load Balancer, and the option does not describe creating one, so the endpoint service cannot be deployed as written. D: AWS Network Manager does not share transit gateways, and invoking Lambda from EventBridge to accept attachments is an unnecessarily complex substitute for a RAM share.

Community Comment Notes

The community voted 93 to 1 for B. Commenters confirmed that VPC endpoint services need an NLB or GWLB, which rules out C, and that RAM is the purpose-built mechanism for sharing a transit gateway with auto-accepted attachments.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide