The organization delegates a specific IP address range for VPC CIDRs and non-cloud hardware. You must prevent principals outside the company IP range from performing AWS actions across the organization’s accounts. Which approach will enforce this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a Service Control Policy (SCP) that denies requests originating from source IP addresses outside the company’s IP range and attach the SCP to the organization root..
Why this is the answer
The correct answer is to create a Service Control Policy (SCP) that denies requests originating from source IP addresses outside the company’s IP range and attach it to the organization root. SCPs are a feature of AWS Organizations that allow you to centrally manage permissions across multiple accounts. By attaching a deny SCP to the organization root, you ensure that no principal, regardless of their IAM permissions, can perform AWS actions if their request originates from an IP address outside the specified range. Using AWS Firewall Manager and Amazon Network Firewall is incorrect because these services primarily control network traffic within or to your VPCs, not API calls made to AWS services from outside the AWS environment. GuardDuty is a threat detection service and does not enforce access control based on IP ranges; its trusted IP list is for reducing false positives in its findings. An SCP that only allows requests from the company IP range is less effective than a deny SCP in this scenario, as a deny SCP explicitly blocks unwanted access, ensuring no other policy can override it to permit access from outside the range.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed