Deny all actions when ec2:MetadataHttpTokens is not required so existing instances lose API access
A company uses an organization in AWS Organizations that has all features enabled to manage its AWS accounts. Amazon EQ instances run in the AWS accounts. The company requires that all current EC2 instances must use Instance Metadata Service Version 2 (IMDSv2). The company needs to block AWS API calls that originate from EC2 instances that do not use IMDSv2. Which solution will meet these requirements?
Community Votes
68% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The distinction between the options is the scope of the deny. Denying only ec2:RunInstances (A) prevents new instances from launching without IMDSv2 but leaves already-running instances free to make API calls, so the stated requirement to block all API calls originating from non-IMDSv2 instances is not met (D). The ec2:RoleDelivery condition key in option C is unrelated to instance metadata tokens. Denying all actions conditioned on ec2:MetadataHttpTokens (D) is what closes both the new and existing instance paths.
The requirement covers all current EC2 instances, including those already running, not only newly launched ones. An SCP that explicitly denies every action when the ec2:MetadataHttpTokens condition key is not equal to required blocks API calls from any instance that is not using IMDSv2, regardless of when it was started. Because the deny applies to all actions rather than only ec2:RunInstances, instances launched before the change lose the ability to make AWS API calls as well.
Denying ec2:RunInstances when ec2:MetadataHttpTokens is not required (A) — this only prevents launching new instances without IMDSv2; instances already running in the accounts can continue making AWS API calls, as both Impromptu and teo2157 noted. Using ec2:MetadataHttpPutResponseHopLimit (B) — that key controls the hop limit for the metadata token PUT response and says nothing about whether the instance uses IMDSv2. Using ec2:RoleDelivery (C) — that key relates to instance profile delivery and is not the metadata token condition key.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement is that all current EC2 instances must use IMDSv2 and that AWS API calls originating from instances that do not use it must be blocked. The service control policy condition key that reflects whether a request used a session token is ec2:MetadataHttpTokens, whose value is required when the request was made with IMDSv2. Writing an SCP statement that explicitly denies all actions when ec2:MetadataHttpTokens is not equal to required therefore blocks every API call made by an instance that is not using IMDSv2, and attaching it at the organization root applies it to every account (D). Because the deny covers all actions and not just ec2:RunInstances, it also neutralizes instances that were launched before the policy existed, which is what the requirement for all current instances demands.Why the Other Options Are Wrong
A denies the ec2:RunInstances action when ec2:MetadataHttpTokens is not equal to required. This prevents new instances from being launched without IMDSv2, but it does nothing to stop instances that are already running from making AWS API calls, so the requirement to block API calls from non-IMDSv2 instances is only partially met; Impromptu and teo2157 both identified this gap. B denies ec2:RunInstances when ec2:MetadataHttpPutResponseHopLimit is greater than two. That condition key governs the hop limit applied to the metadata token PUT response and has no bearing on whether the instance uses IMDSv2, so it would not detect or block the intended requests. C denies all actions when ec2:RoleDelivery is less than two, which is a key related to instance profile delivery and is unrelated to instance metadata tokens, so the condition would not identify non-IMDSv2 callers. Srikantha and DKM favored A, which enforces IMDSv2 only at launch time. D is correct.Community Comment Notes
Community voted D (68), with A a 32 percent minority. Impromptu and teo2157 gave the decisive reasoning, that denying only ec2:RunInstances enforces IMDSv2 merely for newly launched instances while already-running instances can still make AWS API calls, whereas denying all actions on the metadata token condition also covers existing instances. The minority position argued that the SCP correctly prevents launching non-IMDSv2 instances, which addresses only half the requirement.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →