Deny when the EC2 instance source VPC and IP do not match the caller's source VPC and IP via SCP
A company's organization in AWS Organizations has a single OU. The company runs Amazon EC2 instances in the OU accounts. The company needs to limit the use of each EC2 instance’s credentials to the specific EC2 instance that the credential is assigned to. A DevOps engineer must configure security for the EC2 instances. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The pattern requires pairing each instance-side key with its caller-side counterpart: the VPC the credential came from must equal the VPC of the source, and the instance's private IP must equal the source IP, with a deny on any mismatch (B). Option A introduces an unrelated VPC CIDR check and mixes the wrong key pairs. Options C and D attach the SCP to each account rather than the OU, and C additionally substitutes allow-lists of VPC and IP values, which does not compare the credential's origin against its use. The instance-scoped keys ec2:EC2InstanceSourceVPC and ec2:EC2InstanceSourcePrivateIPv4 are what make the comparison possible.
Limiting instance credentials to the instance they belong to requires comparing where the credential was issued against where it is being used. The AWS security guidance for this pattern checks that the aws:EC2InstanceSourceVPC condition key equals the aws:SourceVpc key and that aws:EC2InstanceSourcePrivateIPv4 equals aws:VpcSourceIp, denying access whenever either comparison fails. Applying this SCP to the organizational unit that contains the instances covers them all.
Checking the aws:VpcSourceIp against a VPC CIDR block and mixing aws:EC2InstanceSourcePrivatelPv4 with aws:SourceVpc (A) — this adds a network range condition that is unrelated to binding a credential to its instance and pairs the instance key with the wrong caller key, so it does not implement the intended comparison. Applying the SCP to each account individually (C and D) — as 6ef9a08 noted, the requirement points at the organizational unit, and the account-level attachment in these options is also paired with incorrect key comparisons; RajAWSDevOps007 correctly observed that SCPs can attach to accounts directly, so the decisive fault in C and D is the key pairing, not the attachment point.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The objective is to confine each EC2 instance's credentials to that same instance, which requires proving that a request is coming from the instance the credential was issued to. AWS publishes this pattern, and it works by comparing instance-scoped context keys against the caller's corresponding keys: the aws:EC2InstanceSourceVPC value must equal the aws:SourceVpc value, and the aws:EC2InstanceSourcePrivateIPv4 value must equal the aws:VpcSourceIp value, with the SCP denying access when either comparison fails. Applying that SCP to the organizational unit containing the instances covers every instance in it and satisfies the requirement (B).Why the Other Options Are Wrong
A adds a check that the source IP falls within a specified VPC CIDR block, which is a network range restriction rather than a binding between a credential and its instance, and it pairs aws:EC2InstanceSourcePrivateIPv4 with aws:SourceVpc, mixing an instance key with a VPC key so the comparison is meaningless; fdoxxx identified this unnecessary complexity. C checks whether aws:SourceVpc and aws:VpcSourceIp appear in allow-lists of acceptable values, which constrains where traffic may come from rather than proving the credential came from the calling instance, and it attaches the SCP to each account rather than the OU. D compares aws:EC2InstanceSourceVPC with aws:VpcSourceIp and aws:EC2InstanceSourcePrivateIPv4 with aws:SourceVpc, which again pairs the keys incorrectly by comparing a VPC to an IP and an IP to a VPC. RajAWSDevOps007 correctly noted that SCPs can in fact be attached directly to member accounts, so the fatal flaw in C and D is the key pairing rather than the attachment point. B is the correct answer.Community Comment Notes
Community voted B unanimously. devakram and Diego1414 both cited the AWS Security Blog post on restricting where EC2 instance credentials can be used from and gave the exact key pairings, aws:EC2InstanceSourceVPC equal to aws:SourceVpc and aws:EC2InstanceSourcePrivateIPv4 equal to aws:VpcSourceIp. fdoxxx explained why A's CIDR-based approach adds complexity without providing the intended restriction. Two commenters raised whether SCPs attach to OUs or accounts; 6ef9a08 argued the OU is correct here while RajAWSDevOps007 correctly noted that SCPs can also attach to accounts directly, so that objection does not distinguish C and D from B.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →