Deny AWS actions from source IPs outside the company range with an SCP attached to the organization root

Answer Correct answer: B — attach an SCP to the organization root denying requests whose source IP is outside the company range.

A company operates sensitive workloads across the AWS accounts that are in the company's organization in AWS Organizations. The company uses an IP address range to delegate IP addresses for Amazon VPC CIDR blocks and all non-cloud hardware. The company needs a solution that prevents principals that are outside the company’s IP address range from performing AWS actions in the organization's accounts. Which solution will meet these requirements?

  1. Configure AWS Firewall Manager for the organization. Create an AWS Network Firewall policy that allows only source traffic from the company's IP address range. Set the policy scope to all accounts in the organization.
  2. In Organizations, create an SCP that denies source IP addresses that are outside of the company’s IP address range. Attach the SCP to the organization's root. Correct Answer
  3. Configure Amazon GuardDuty for the organization. Create a GuardDuty trusted IP address list for the company's IP range. Activate the trusted IP list for the organization.
  4. In Organizations, create an SCP that allows source IP addresses that are inside of the company’s IP address range. Attach the SCP to the organization's root.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The requirement is a deny based on where the request originates, which is exactly what an SCP with a NotIpAddress condition on the aws:SourceIp key provides, and attaching it at the organization root applies it to every account in one place (B). Option D is the mirror image and is ineffective: an SCP never grants permissions, so allowing a source IP range does not restrict anything and everything not explicitly denied remains allowed by the FullAWSAccess default. Options A and C use services that report or detect network activity rather than gate AWS API authorization.

The company delegates a known IP range for its VPC CIDR blocks and all non-cloud hardware, and needs to prevent any principal outside that range from performing AWS actions in the organization's accounts. A service control policy that denies requests whose source IP address is outside the company's range and attaches to the organization root enforces this centrally, using the aws:SourceIp condition key so the deny applies to every account without touching any individual account.

Creating an SCP that allows source IP addresses inside the company's range (D) — service control policies only define the maximum available permissions and never grant them, so an allow statement for a source IP range restricts nothing; the deny in B is what actually removes access. Configuring AWS Firewall Manager with a Network Firewall policy allowing only the company range (A) — Firewall Manager governs network security policies such as firewall rules and security group policies, not the source IP from which AWS API calls are authorized. Configuring GuardDuty with a trusted IP list (C) — a trusted IP list suppresses findings for known sources; it does not prevent those sources or any other source from performing AWS actions.

Community Discussion (5 comments)

WhyIronMan 👍 5 Selected: B
B https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_examples_aws_deny-ip.html
seetpt 👍 3 Selected: B
B 100%
c3518fc 👍 4 Selected: B
https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_examples_aws_deny-ip.html
dkp 👍 4 Selected: B
answer b uses an SCP within AWS Organizations to deny source IP addresses that are outside of the company’s IP address range, providing a centralized and organization-wide control over AWS actions based on source IP addresses for all accounts and resources within the organization.
ogerber 👍 2
its B, 100%

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement is to prevent principals outside the company's delegated IP range from performing AWS actions in any account in the organization. AWS provides a documented pattern for this: an explicit deny in a service control policy using a NotIpAddress condition on the aws:SourceIp global condition key, so any request originating outside the company's range is rejected before it is authorized (B). Because an SCP attached at the organization root is inherited by every organizational unit and account beneath it, a single policy enforces the restriction across the entire organization with no per-account configuration, which is what makes it the appropriate central control. Deny rather than allow is essential because an SCP sets a ceiling on permissions and never grants them, so only a deny removes access.

Why the Other Options Are Wrong

D creates an SCP that allows source IP addresses inside the company's range. This is ineffective because SCPs do not grant permissions; an allow statement in an SCP cannot enable anything that identity-based policies do not already permit, and it does not restrict anything. With the default FullAWSAccess policy in place, requests from outside the range remain allowed, so the requirement is not met. A configures AWS Firewall Manager for the organization with an AWS Network Firewall policy that allows only source traffic from the company's range. Firewall Manager centrally manages network security policies such as firewall rules and security group policies across accounts, but source-IP-based authorization of AWS API calls is an IAM concern, so this does not prevent principals outside the range from performing AWS actions. C configures GuardDuty with a trusted IP list for the company range and activates it for the organization. A GuardDuty trusted IP list suppresses findings for traffic from those addresses; it has no effect on whether those or any other addresses are authorized to call AWS APIs. B is the correct answer.

Community Comment Notes

Community voted B unanimously. WhyIronMan and c3518fc both cited the IAM documentation page for the example policy that denies actions based on source IP address, which is the documented mechanism. seetpt and ogerber confirmed B without further qualification. dkp explained that using an SCP within AWS Organizations provides a centralized, organization-wide control over AWS actions based on source IP address, which is exactly what the requirement describes. No alternative option received support.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide