Shared Amazon SageMaker Studio notebooks are reachable only via a VPN. The company must enforce access controls to stop attackers from using presigned URLs to reach the notebooks. Which configuration meets this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Enforce Studio client IP validation by using the aws:sourceIp IAM policy condition..
Why this is the answer
The correct option is to enforce Studio client IP validation using the aws:SourceIp IAM policy condition. This condition allows you to specify a range of IP addresses from which requests are permitted, effectively restricting access to users connected via the company's VPN, which would have a known set of IP addresses. This prevents attackers from using presigned URLs from outside the approved network. The aws:sourceVpc condition is incorrect because SageMaker Studio notebooks are typically accessed over the internet, not directly from a VPC endpoint, making VPC validation less effective for this scenario. The aws:PrimaryTag and aws:PrincipalTag conditions are used for resource or principal tagging and do not directly control network access based on IP addresses, making them unsuitable for enforcing VPN-based access control.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed