Connecting 50 growing VPCs and exposing license validation via PrivateLink
A software as a service (SaaS) company provides a media software solution to customers. The solution is hosted on 50 VPCs across various AWS Regions and AWS accounts. One of the VPCs is designated as a management VPC. The compute resources in the VPCs work independently. The company has developed a new feature that requires all 50 VPCs to be able to communicate with each other. The new feature also requires one-way access from each customer's VPC to the company's management VPC. The management VPC hosts a compute resource that validates licenses for the media software solution. The number of VPCs that the company will use to host the solution will continue to increase as the solution grows. Which combination of steps will provide the required VPC connectivity with the LEAST operational overhead? (Choose two.)
Community Votes
71% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
For a growing multi-VPC mesh, Transit Gateway scales far better than O(n^2) peering; PrivateLink is the purpose-built one-way mechanism to expose a central service to many consumer VPCs.
Fifty VPCs across Regions/accounts need full mesh connectivity plus one-way access to a management VPC for license validation, scaling as VPCs grow. A transit gateway provides scalable full mesh, and an NLB with PrivateLink exposes the license service one-way to each customer VPC.
Choosing VPC peering (Options B/E) — full-mesh peering does not scale as VPC count grows and adds heavy operational overhead versus a transit gateway.
Community Discussion (14 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option A creates a transit gateway and attaches all VPCs (with inter-Region TGW peering where needed), giving a scalable full mesh. Option C creates an NLB for license validation and a PrivateLink endpoint service, providing one-way, managed access from each customer VPC to the management VPC without bidirectional peering.Why the Other Options Are Wrong
Option B (full peering) and E (management peering) do not scale and create excessive operational overhead as VPCs grow. Option D (VPN appliances per VPC) is costly and high-touch. PrivateLink is explicitly designed for one-way service exposure.Community Comment Notes
The vote is AC (67) over BC (28). Spike2020 argued BC citing TGW as regional, but TGW supports inter-Region peering, and nimbus_00 notes PrivateLink now supports cross-Region. JoeTromundo confirms TGW inter-Region peering.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →