Connecting 50 growing VPCs and exposing license validation via PrivateLink

Answer Correct answer: A, C — Use a transit gateway to mesh all 50 VPCs scalably and expose license validation via an NLB and PrivateLink for one-way access to the management VPC.

A software as a service (SaaS) company provides a media software solution to customers. The solution is hosted on 50 VPCs across various AWS Regions and AWS accounts. One of the VPCs is designated as a management VPC. The compute resources in the VPCs work independently. The company has developed a new feature that requires all 50 VPCs to be able to communicate with each other. The new feature also requires one-way access from each customer's VPC to the company's management VPC. The management VPC hosts a compute resource that validates licenses for the media software solution. The number of VPCs that the company will use to host the solution will continue to increase as the solution grows. Which combination of steps will provide the required VPC connectivity with the LEAST operational overhead? (Choose two.)

  1. Create a transit gateway. Attach all the company's VPCs and relevant subnets to the transit gateway. Correct Answer
  2. Create VPC peering connections between all the company's VPCs.
  3. Create a Network Load Balancer (NLB) that points to the compute resource for license validation. Create an AWS PrivateLink endpoint service that is available to each customer's VPAssociate the endpoint service with the NLB. Correct Answer
  4. Create a VPN appliance in each customer's VPC. Connect the company's management VPC to each customer's VPC by using AWS Site-to-Site VPN.
  5. Create a VPC peering connection between the company's management VPC and each customer's VPC.

Community Votes

AC
71%
BC
29%

71% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

For a growing multi-VPC mesh, Transit Gateway scales far better than O(n^2) peering; PrivateLink is the purpose-built one-way mechanism to expose a central service to many consumer VPCs.

Fifty VPCs across Regions/accounts need full mesh connectivity plus one-way access to a management VPC for license validation, scaling as VPCs grow. A transit gateway provides scalable full mesh, and an NLB with PrivateLink exposes the license service one-way to each customer VPC.

Choosing VPC peering (Options B/E) — full-mesh peering does not scale as VPC count grows and adds heavy operational overhead versus a transit gateway.

Community Discussion (14 comments)

Spike2020 👍 2 Selected: BC
Private link for the customers and vpc peering for company VPCs. Transit gateway is only a regional construct.
nimbus_00 👍 1 Selected: AC
AWS PrivateLink now supports cross-region connectivity https://aws.amazon.com/about-aws/whats-new/2024/11/aws-privatelink-across-region-connectivity/
0b43291 👍 1 Selected: AC
A. Create a transit gateway. Attach all the company's VPCs to it, establishing a mesh network where VPCs can communicate. This provides a scalable way to manage VPC connectivity, reducing operational overhead compared to VPC peering. C. Create a Network Load Balancer (NLB) for the license validation compute resource. Create an AWS PrivateLink endpoint service associated with the NLB, available to each customer's VPC. This provides one-way access from customer VPCs to the management VPC for license validation, without internet gateways, NAT gateways, or VPNs. It simplifies network configuration and reduces operational overhead.
JoeTromundo 👍 2 Selected: AC
AWS Transit Gateway supports peering between transit gateways in different regions. This means that you can connect a Transit Gateway in one region to another Transit Gateway in a different region. This feature is known as Transit Gateway Peering (not VPC peering). AWS Transit Gateway also allows you to associate VPCs from different AWS accounts to the same transit gateway using AWS Resource Access Manager (RAM)
helloworldabc 👍 2
AAAAAAAAAAACCCCCCCCC
ca5e9ba 👍 4
AC; AWS Transit Gateway allows you to connect resources across different AWS regions. Here’s how you can achieve this: Create Transit Gateways: Begin by creating Transit Gateways in the respective regions where you want to establish peering. Ensure that the necessary VPCs are attached to each Transit Gateway. Enable Peering: Navigate to the AWS Management Console and select the Transit Gateway service. Initiate the peering connection between the two Transit Gateways in different regions. Update Route Tables: Configure the route tables associated with each Transit Gateway to allow traffic between the regions. Security Groups and Network ACLs: Adjust security groups and network ACLs to permit the necessary traffic flow. Connectivity Testing: Verify connectivity by testing communication between resources in different regions.
teo2157 👍 1 Selected: BC
As titi_r explained
titi_r 👍 2 Selected: BC
B – Correct, even that it will be a routing madness. The default VPC peering quota is 50, but increasable after request to 125. So, the company will be able to peer its 50 VPCs, but it must request a quota increase for a higher number - that’s not mentioned in the answer. And also what’s happening when/if they require more than 125 VPCs at one point? https://docs.aws.amazon.com/vpc/latest/peering/vpc-peering-connection-quotas.html - C – Correct. The PrivateLink endpoint service will provide a one-way access from each customer's VPC to the company's management VPC. https://docs.aws.amazon.com/whitepapers/latest/aws-privatelink/use-case-examples.html
trap 👍 4
It SHOULD be transit gateway but it isn't. The VPCs are hosted in several accounts and regions. You can't attach all VPCs in one transit gateway. You need several peered transit gws per region which is not the case here. Correct: B,C
Russs99 👍 1 Selected: AE
NLB and PrivateLink offer benefits, they are overkill for this scenario. NLB is for distributing traffic across multiple instances, which isn't necessary here. PrivateLink creates a private connection for a service within a VPC, but it's a more complex solution than a simple peering connection for the management VPC.
career360guru 👍 2 Selected: AC
A and C
arberod 👍 3 Selected: AC
answer AC
kejam 👍 3 Selected: AC
Answer AC: Transit Gateway and Private Link for the WIN!
alexis123456 👍 4
Correct Answer A and C

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option A creates a transit gateway and attaches all VPCs (with inter-Region TGW peering where needed), giving a scalable full mesh. Option C creates an NLB for license validation and a PrivateLink endpoint service, providing one-way, managed access from each customer VPC to the management VPC without bidirectional peering.

Why the Other Options Are Wrong

Option B (full peering) and E (management peering) do not scale and create excessive operational overhead as VPCs grow. Option D (VPN appliances per VPC) is costly and high-touch. PrivateLink is explicitly designed for one-way service exposure.

Community Comment Notes

The vote is AC (67) over BC (28). Spike2020 argued BC citing TGW as regional, but TGW supports inter-Region peering, and nimbus_00 notes PrivateLink now supports cross-Region. JoeTromundo confirms TGW inter-Region peering.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide