Update S3 bucket policies to the new IP range and deny S3 access with an SCP on the two OUs

Answer Correct answer: C — update the bucket policies to the new IP range and attach an SCP denying S3 access to the two organizational units.

A company manages multiple AWS accounts by using AWS Organizations with OUs for the different business divisions. The company is updating their corporate network to use new IP address ranges. The company has 10 Amazon S3 buckets in different AWS accounts. The S3 buckets store reports for the different divisions. The S3 bucket configurations allow only private corporate network IP addresses to access the S3 buckets. A DevOps engineer needs to change the range of IP addresses that have permission to access the contents of the S3 buckets. The DevOps engineer also needs to revoke the permissions of two OUs in the company. Which solution will meet these requirements?

  1. Create a new SCP that has two statements, one that allows access to the new range of IP addresses for all the S3 buckets and one that denies access to the old range of IP addresses for all the S3 buckets. Set a permissions boundary for the OrganizationAccountAccessRole role in the two OUs to deny access to the S3 buckets.
  2. Create a new SCP that has a statement that allows only the new range of IP addresses to access the S3 buckets. Create another SCP that denies access to the S3 buckets. Attach the second SCP to the two OUs.
  3. On all the S3 buckets, configure resource-based policies that allow only the new range of IP addresses to access the S3 buckets. Create a new SCP that denies access to the S3 buckets. Attach the SCP to the two OUs. Correct Answer
  4. On all the S3 buckets, configure resource-based policies that allow only the new range of IP addresses to access the S3 buckets. Set a permissions boundary for the OrganizationAccountAccessRole role in the two OUs to deny access to the S3 buckets.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The two requirements map to two different policy types. Restricting source IP ranges is inherently a resource-based policy control using aws:SourceIp or aws:VpcSourceIp, so the change belongs in the bucket policies (C and D). Restricting entire organizational units is an IAM Organizations guardrail, and SCPs attach to OUs and act as a maximum-permissions boundary, so the second half requires an SCP on the two OUs. Only option C combines the correct mechanism for both halves.

Two distinct changes are required: updating the permitted corporate IP range on the ten S3 buckets, and revoking S3 access for two organizational units. IP-range conditions are expressed in resource-based policies, so the bucket policies on each bucket must be changed to allow only the new range and stop allowing the old one. Restricting access by organizational unit is an authorization-boundary concern, so a new SCP denying access to the S3 buckets is attached to the two OUs, since SCPs can be targeted at specific OUs and cannot be overridden by account-level permissions.

Trying to change the permitted IP ranges with an SCP (A and B) — SCPs cannot evaluate the aws:SourceIp context key against S3 requests, so the bucket's resource-based policy is the only place the IP restriction can be expressed. Using a permissions boundary on OrganizationAccountAccessRole (A and D) — a boundary caps what a principal may do but does not deny access for the OUs' own principals, so it does not revoke S3 access for those organizational units. B's second SCP that simply denies S3 access would also revoke access from every division, not just the two named OUs.

Community Discussion (6 comments)

Srikantha 👍 1 Selected: D
On all the S3 buckets, configure resource-based policies that allow only the new range of IP addresses to access the S3 buckets. Set a permissions boundary for the OrganizationAccountAccessRole role in the two OUs to deny access to the S3 buckets. This solution meets the requirements most effectively: The resource-based S3 bucket policies ensure that only the new IP address ranges are allowed access, effectively controlling access at the network level. By setting a permissions boundary on the OrganizationAccountAccessRole role, the OUs' permissions to the S3 buckets can be explicitly controlled and revoked, ensuring that only the appropriate accounts have access.
seetpt 👍 3 Selected: C
C for me
dkp 👍 4 Selected: C
answer c
Ola2234 👍 1
C. Use bucket policy to allow or deny access to a range of IP addresses or VPC endpoints to an S3 resource. Restriction to OUs is best done using SCP.
ogerber 👍 4 Selected: C
C for me
Seoyong 👍 4 Selected: C
restrict access to S3 bucket using specific VPC endpoints or IP addresses: https://repost.aws/knowledge-center/block-s3-traffic-vpc-ip

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement has two parts. First, the range of IP addresses permitted to read the report buckets must change from the old corporate range to the new one; since source-IP restrictions are expressed through resource-based policy conditions such as aws:SourceIp, this change must be made in the bucket policies of the ten S3 buckets, allowing only the new range. Second, S3 access must be revoked for two specific organizational units; organizational-unit-scoped restrictions are enforced with an SCP attached to those two OUs, because an SCP acts as a maximum-permissions boundary for every principal in the accounts beneath it and cannot be overridden by any identity-based or resource-based allow. Option C does exactly these two things.

Why the Other Options Are Wrong

A proposes implementing the new IP range with an SCP. SCPs are evaluated for API authorization and cannot enforce source-IP conditions on S3 data-plane requests, so the IP restriction would not take effect. B also implements the IP change with SCPs and then attaches a blanket deny of S3 access to the two OUs, which would revoke S3 access for those units but leaves the IP change unimplemented and strips the other divisions' intended access model. D updates the bucket policies correctly but attempts the OU revocation with a permissions boundary on the OrganizationAccountAccessRole role, which caps that management role rather than denying S3 access for the OUs' principals. C is the correct answer.

Community Comment Notes

Community voted C (94). Commenters agreed the bucket resource-based policies are the only place an IP-range condition can be set, and that restricting specific organizational units is best done with an SCP attached to those OUs. Srikantha proposed D, but a permissions boundary on OrganizationAccountAccessRole does not revoke access for the OUs' own principals.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide