Share a Transit Gateway with AWS RAM for a self-service cross-account connection
A company uses an organization in AWS Organizations to manage multiple AWS accounts. The company hosts some applications in a VPC in the company's shared services account. The company has attached a transit gateway to the VPC in the shared services account. The company is developing a new capability and has created a development environment that requires access to the applications that are in the shared services account. The company intends to delete and recreate resources frequently in the development account. The company also wants to give a development team the ability to recreate the team's connection to the shared services account as required. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
AWS RAM shares the existing transit gateway rather than creating a new one, so the development team creates and deletes its own attachments on the shared gateway without any cross-account request workflow.
A development account needs access to applications in a shared services VPC that is attached to a transit gateway. Resources in the development account are created and destroyed frequently, and the team must be able to re-establish its own connection on demand.
Creating a second transit gateway in the development account and peering the two. That adds a gateway and a peering relationship to manage, and the connection cannot be re-established by the development team alone because peering acceptance lives in the other account.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
AWS RAM can share a transit gateway with another account, and automatic acceptance makes the resource share available without a manual accept step in the shared account. The development team then creates its own transit gateway attachment whenever it needs connectivity and deletes it when the environment is torn down, which is exactly the self-service requirement.Why the Other Options Are Wrong
A: Creating a transit gateway in the development account and peering it adds an extra gateway plus a peering relationship to maintain, and it does not give the development team on-demand control over the connection. C: A VPC endpoint service requires a Network Load Balancer or a Gateway Load Balancer, and the option does not describe creating one, so the endpoint service cannot be deployed as written. D: AWS Network Manager does not share transit gateways, and invoking Lambda from EventBridge to accept attachments is an unnecessarily complex substitute for a RAM share.Community Comment Notes
The community voted 93 to 1 for B. Commenters confirmed that VPC endpoint services need an NLB or GWLB, which rules out C, and that RAM is the purpose-built mechanism for sharing a transit gateway with auto-accepted attachments.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →