Deny all actions when ec2:MetadataHttpTokens is not required so existing instances lose API access

Answer Correct answer: D — deny all actions when ec2:MetadataHttpTokens is not required, blocking API calls from existing non-IMDSv2 instances.

A company uses an organization in AWS Organizations that has all features enabled to manage its AWS accounts. Amazon EQ instances run in the AWS accounts. The company requires that all current EC2 instances must use Instance Metadata Service Version 2 (IMDSv2). The company needs to block AWS API calls that originate from EC2 instances that do not use IMDSv2. Which solution will meet these requirements?

  1. Create a new SCP statement that denies the ec2:RunInstances action when the ec2:MetadataHttpTokens condition key is not equal to the value of required. Attach the SCP to the root of the organization.
  2. Create a new SCP statement that denies the ec2:RunInstances action when the ec2:MetadataHttpPutResponseHopLimit condition key value is greater than two. Attach the SCP to the root of the organization.
  3. Create a new SCP statement that denies "*" when the ec2:RoleDelivery condition key value is less than two. Attach the SCP to the root of the organization.
  4. Create a new SCP statement that denies when the ec2:MetadataHttpTokens condition key value is not equal to required. Attach the SCP to the root of the organization. Correct Answer

Community Votes

D
68%
A
32%

68% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The distinction between the options is the scope of the deny. Denying only ec2:RunInstances (A) prevents new instances from launching without IMDSv2 but leaves already-running instances free to make API calls, so the stated requirement to block all API calls originating from non-IMDSv2 instances is not met (D). The ec2:RoleDelivery condition key in option C is unrelated to instance metadata tokens. Denying all actions conditioned on ec2:MetadataHttpTokens (D) is what closes both the new and existing instance paths.

The requirement covers all current EC2 instances, including those already running, not only newly launched ones. An SCP that explicitly denies every action when the ec2:MetadataHttpTokens condition key is not equal to required blocks API calls from any instance that is not using IMDSv2, regardless of when it was started. Because the deny applies to all actions rather than only ec2:RunInstances, instances launched before the change lose the ability to make AWS API calls as well.

Denying ec2:RunInstances when ec2:MetadataHttpTokens is not required (A) — this only prevents launching new instances without IMDSv2; instances already running in the accounts can continue making AWS API calls, as both Impromptu and teo2157 noted. Using ec2:MetadataHttpPutResponseHopLimit (B) — that key controls the hop limit for the metadata token PUT response and says nothing about whether the instance uses IMDSv2. Using ec2:RoleDelivery (C) — that key relates to instance profile delivery and is not the metadata token condition key.

Community Discussion (7 comments)

Impromptu 👍 5 Selected: D
I think it's D. It must indeed use the ec2:MetadataHttpTokens condition key, but if we only deny the ec2:RunInstances, then the already running EC2 instances can still do AWS API calls. Even if they are not using IMDSv2.
teo2157 👍 5 Selected: D
Going for D, as A just enforce that the new EC2 instances to use IMDSv2 but there can be old instances not running IDMSv2 that can still do API calls...
Srikantha 👍 1 Selected: A
Service Control Policies (SCPs) allow you to control which actions are allowed or denied across an entire organization or specific organizational units (OUs) in AWS Organizations. The ec2:MetadataHttpTokens condition key is used to enforce IMDSv2. Setting the value of required ensures that the EC2 instances launched must use IMDSv2, as IMDSv1 would be denied. By denying ec2:RunInstances when the IMDSv2 condition is not met, you are enforcing the policy for all EC2 instances launched, preventing the creation of instances without IMDSv2.
DKM 👍 1 Selected: A
This Service Control Policy (SCP) ensures that any attempt to launch EC2 instances without using IMDSv2 will be denied. By attaching this SCP to the root of the organization, it will apply to all accounts within the organization, ensuring compliance across the board. Here is an example of the SCP statement: { "Version": "2012-10-17", "Statement": [ { "Effect": "Deny", "Action": "ec2:RunInstances", "Resource": "*", "Condition": { "StringNotEquals": { "ec2:MetadataHttpTokens": "required" } } } ] }
DKM 👍 1 Selected: A
Here's why: Service Control Policies (SCPs): SCPs allow you to set permission guardrails for all accounts in your organization. By creating an SCP that denies the ec2:RunInstances action when the ec2:MetadataHttpTokens condition key is not set to required, you ensure that only instances configured to use IMDSv2 can be launched1. Condition Key: The ec2:MetadataHttpTokens condition key ensures that the instance metadata service requires the use of IMDSv21. This approach enforces the use of IMDSv2 across all EC2 instances in the organization, enhancing security by preventing the use of the less secure IMDSv1.
CHRIS12722222 👍 3 Selected: D
Option A will prevent creating ec2 instances, allowing existing ones to violate policy
uncledana 👍 3 Selected: A
Option A provides the correct solution by using the ec2:MetadataHttpTokens condition key in an SCP to deny the ec2:RunInstances action for instances that do not have IMDSv2 enabled. This is the most effective way to ensure compliance with the company’s requirement.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement is that all current EC2 instances must use IMDSv2 and that AWS API calls originating from instances that do not use it must be blocked. The service control policy condition key that reflects whether a request used a session token is ec2:MetadataHttpTokens, whose value is required when the request was made with IMDSv2. Writing an SCP statement that explicitly denies all actions when ec2:MetadataHttpTokens is not equal to required therefore blocks every API call made by an instance that is not using IMDSv2, and attaching it at the organization root applies it to every account (D). Because the deny covers all actions and not just ec2:RunInstances, it also neutralizes instances that were launched before the policy existed, which is what the requirement for all current instances demands.

Why the Other Options Are Wrong

A denies the ec2:RunInstances action when ec2:MetadataHttpTokens is not equal to required. This prevents new instances from being launched without IMDSv2, but it does nothing to stop instances that are already running from making AWS API calls, so the requirement to block API calls from non-IMDSv2 instances is only partially met; Impromptu and teo2157 both identified this gap. B denies ec2:RunInstances when ec2:MetadataHttpPutResponseHopLimit is greater than two. That condition key governs the hop limit applied to the metadata token PUT response and has no bearing on whether the instance uses IMDSv2, so it would not detect or block the intended requests. C denies all actions when ec2:RoleDelivery is less than two, which is a key related to instance profile delivery and is unrelated to instance metadata tokens, so the condition would not identify non-IMDSv2 callers. Srikantha and DKM favored A, which enforces IMDSv2 only at launch time. D is correct.

Community Comment Notes

Community voted D (68), with A a 32 percent minority. Impromptu and teo2157 gave the decisive reasoning, that denying only ec2:RunInstances enforces IMDSv2 merely for newly launched instances while already-running instances can still make AWS API calls, whereas denying all actions on the metadata token condition also covers existing instances. The minority position argued that the SCP correctly prevents launching non-IMDSv2 instances, which addresses only half the requirement.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide