Deny when the EC2 instance source VPC and IP do not match the caller's source VPC and IP via SCP

Answer Correct answer: B — deny when the instance source VPC and private IP do not match the caller's source VPC and IP, applied to the OU.

A company's organization in AWS Organizations has a single OU. The company runs Amazon EC2 instances in the OU accounts. The company needs to limit the use of each EC2 instance’s credentials to the specific EC2 instance that the credential is assigned to. A DevOps engineer must configure security for the EC2 instances. Which solution will meet these requirements?

  1. Create an SCP that specifies the VPC CIDR block. Configure the SCP to check whether the value of the aws:VpcSourcelp condition key is in the specified block. In the same SCP check, check whether the values of the aws:EC2InstanceSourcePrivatelPv4 and aws:SourceVpc condition keys are the same. Deny access if either condition is false. Apply the SCP to the OU.
  2. Create an SCP that checks whether the values of the aws:EC2InstanceSourceVPC and aws:SourceVpc condition keys are the same. Deny access if the values are not the same. In the same SCP check, check whether the values of the aws:EC2InstanceSourcePrivateIPv4 and aws:VpcSourceIp condition keys are the same. Deny access if the values are not the same. Apply the SCP to the OU. Correct Answer
  3. Create an SCP that includes a list of acceptable VPC values and checks whether the value of the aws:SourceVpc condition key is in the list. In the same SCP check, define a list of acceptable IP address values and check whether the value of the aws:VpcSourceIp condition key is in the list. Deny access if either condition is false. Apply the SCP to each account in the organization.
  4. Create an SCP that checks whether the values of the aws:EC2InstanceSourceVPC and aws:VpcSourceIp condition keys are the same. Deny access if the values are not the same. In the same SCP check, check whether the values of the aws:EC2InstanceSourcePrivateIPv4 and aws:SourceVpc condition keys are the same. Deny access if the values are not the same. Apply the SCP to each account in the organization.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The pattern requires pairing each instance-side key with its caller-side counterpart: the VPC the credential came from must equal the VPC of the source, and the instance's private IP must equal the source IP, with a deny on any mismatch (B). Option A introduces an unrelated VPC CIDR check and mixes the wrong key pairs. Options C and D attach the SCP to each account rather than the OU, and C additionally substitutes allow-lists of VPC and IP values, which does not compare the credential's origin against its use. The instance-scoped keys ec2:EC2InstanceSourceVPC and ec2:EC2InstanceSourcePrivateIPv4 are what make the comparison possible.

Limiting instance credentials to the instance they belong to requires comparing where the credential was issued against where it is being used. The AWS security guidance for this pattern checks that the aws:EC2InstanceSourceVPC condition key equals the aws:SourceVpc key and that aws:EC2InstanceSourcePrivateIPv4 equals aws:VpcSourceIp, denying access whenever either comparison fails. Applying this SCP to the organizational unit that contains the instances covers them all.

Checking the aws:VpcSourceIp against a VPC CIDR block and mixing aws:EC2InstanceSourcePrivatelPv4 with aws:SourceVpc (A) — this adds a network range condition that is unrelated to binding a credential to its instance and pairs the instance key with the wrong caller key, so it does not implement the intended comparison. Applying the SCP to each account individually (C and D) — as 6ef9a08 noted, the requirement points at the organizational unit, and the account-level attachment in these options is also paired with incorrect key comparisons; RajAWSDevOps007 correctly observed that SCPs can attach to accounts directly, so the decisive fault in C and D is the key pairing, not the attachment point.

Community Discussion (9 comments)

devakram 👍 5 Selected: B
B obviously : https://aws.amazon.com/blogs/security/how-to-use-policies-to-restrict-where-ec2-instance-credentials-can-be-used-from/
RajAWSDevOps007 👍 1
Answer is B here. However, pls note SCPs can be applied directly to member accounts as well- https://docs.aws.amazon.com › orgs_manage_policies_scps
6ef9a08 👍 1
NOT C,D: "Apply the SCP to each account in the organization" - SCPs apply to OUs, not accounts
fdoxxx 👍 4 Selected: B
B is the most appropriate solution: Option A introduces unnecessary complexity with multiple conditions and may not provide the intended restriction. Option C suggests creating an SCP with lists of acceptable values, but it might be challenging to maintain and is less straightforward. Option D has the same issues as option A, introducing complexity with multiple conditions.
Diego1414 👍 4 Selected: B
Answer: B - aws:EC2InstanceSourceVPC = aws:SourceVpc and aws:EC2InstanceSourcePrivateIPv4 = aws:VpcSourceIp https://aws.amazon.com/blogs/security/how-to-use-policies-to-restrict-where-ec2-instance-credentials-can-be-used-from/
thanhnv142 👍 4 Selected: B
B is correct: aws:EC2InstanceSourceVPC and aws:SourceVpc must be the same. Additionally, aws:EC2InstanceSourcePrivateIPv4 and aws:VpcSourceIp must be the same A: irrelevant C: <define a list of acceptable IP address values> is not correct D: <aws:EC2InstanceSourceVPC and aws:VpcSourceIp> is incorrect
vortegon 👍 2 Selected: B
https://aws.amazon.com/fr/blogs/security/how-to-use-policies-to-restrict-where-ec2-instance-credentials-can-be-used-from/
Chelseajcole 👍 1
B. checks whether the values of the aws:EC2InstanceSourceVPC and aws:SourceVpc condition keys are the same and Apply the SCP to the OU.
Arnaud92 👍 1
Source: https://aws.amazon.com/fr/blogs/security/how-to-use-policies-to-restrict-where-ec2-instance-credentials-can-be-used-from/

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The objective is to confine each EC2 instance's credentials to that same instance, which requires proving that a request is coming from the instance the credential was issued to. AWS publishes this pattern, and it works by comparing instance-scoped context keys against the caller's corresponding keys: the aws:EC2InstanceSourceVPC value must equal the aws:SourceVpc value, and the aws:EC2InstanceSourcePrivateIPv4 value must equal the aws:VpcSourceIp value, with the SCP denying access when either comparison fails. Applying that SCP to the organizational unit containing the instances covers every instance in it and satisfies the requirement (B).

Why the Other Options Are Wrong

A adds a check that the source IP falls within a specified VPC CIDR block, which is a network range restriction rather than a binding between a credential and its instance, and it pairs aws:EC2InstanceSourcePrivateIPv4 with aws:SourceVpc, mixing an instance key with a VPC key so the comparison is meaningless; fdoxxx identified this unnecessary complexity. C checks whether aws:SourceVpc and aws:VpcSourceIp appear in allow-lists of acceptable values, which constrains where traffic may come from rather than proving the credential came from the calling instance, and it attaches the SCP to each account rather than the OU. D compares aws:EC2InstanceSourceVPC with aws:VpcSourceIp and aws:EC2InstanceSourcePrivateIPv4 with aws:SourceVpc, which again pairs the keys incorrectly by comparing a VPC to an IP and an IP to a VPC. RajAWSDevOps007 correctly noted that SCPs can in fact be attached directly to member accounts, so the fatal flaw in C and D is the key pairing rather than the attachment point. B is the correct answer.

Community Comment Notes

Community voted B unanimously. devakram and Diego1414 both cited the AWS Security Blog post on restricting where EC2 instance credentials can be used from and gave the exact key pairings, aws:EC2InstanceSourceVPC equal to aws:SourceVpc and aws:EC2InstanceSourcePrivateIPv4 equal to aws:VpcSourceIp. fdoxxx explained why A's CIDR-based approach adds complexity without providing the intended restriction. Two commenters raised whether SCPs attach to OUs or accounts; 6ef9a08 argued the OU is correct here while RajAWSDevOps007 correctly noted that SCPs can also attach to accounts directly, so that objection does not distinguish C and D from B.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide