Restrict Amazon WorkSpaces access with an IP access control group

Answer Correct answer: A — Create an IP access control group with the branch office public addresses and associate it with the WorkSpaces directory.

A company wants to use Amazon WorkSpaces in combination with thin client devices to replace aging desktops. Employees use the desktops to access applications that work with Clinical trial data. Corporate security policy states that access to the applications must be restricted to only company branch office locations. The company is considering adding an additional branch office in the next 6 months. Which solution meets these requirements with the MOST operational efficiency?

  1. Create an IP access control group rule with the list of public addresses from the branch offices. Associate the IP access control group with the WorkSpaces directory. Correct Answer
  2. Use AWS Firewall Manager to create a web ACL rule with an IPSet with the list of public addresses from the branch office locations. Associate the web ACL with the WorkSpaces directory.
  3. Use AWS Certificate Manager (ACM) to issue trusted device certificates to the machines deployed in the branch office locations. Enable restricted access on the WorkSpaces directory.
  4. Create a custom WorkSpace image with Windows Firewall configured to restrict access to the public addresses of the branch offices. Use the image to deploy the WorkSpaces.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

An IP access control group is a native WorkSpaces directory feature, so associating the office public IPs with the directory is a configuration change that the same team repeats when the new branch opens.

Thin client WorkSpaces must reach clinical trial applications only from company branch office locations, and a new branch office is planned within six months. The control must be centrally managed so the new location is added without rebuilding images.

Reaching for AWS Firewall Manager with a web ACL. Firewall Manager and WAF web ACLs operate on HTTP and HTTPS requests and are not applied to WorkSpaces client connections, so they cannot restrict access to a WorkSpaces directory.

Community Discussion (13 comments)

backbencher2022 👍 3 Selected: A
A is correct. B is incorrect because WAF web ACLs don't work with Amazon Workspaces. A web access control list (web ACL) gives you fine-grained control over all of the HTTP(S) web requests that your protected resource responds to. You can protect Amazon CloudFront, Amazon API Gateway, Application Load Balancer, AWS AppSync, Amazon Cognito, AWS App Runner, and AWS Verified Access resources. https://docs.aws.amazon.com/waf/latest/developerguide/web-acl.html
trungtd 👍 2 Selected: A
This is not usecase of AWS Firewall Manager and web ACL, and A work
iulian0585 👍 1 Selected: A
B. AWS Firewall Manager and web ACL: While this could work, it is generally used for managing rules across multiple AWS accounts and resources, which might be an overcomplication for this specific use case. It is more complex to set up and manage compared to IP access control groups.
red_panda 👍 1 Selected: B
From an operational simplicity point of view (which is what is required) it is clearly B. It is much easier to manage IPs with Firewall manager than in a custom way, which by the way remains vague. For me, the correct answer is B.
titi_r 👍 3 Selected: A
Answer: A From the AWS Console: "Create an IP access control group that you can add to a WorkSpaces Directory. Users will only be able to access WorkSpaces from these IP addresses."
tushar321 👍 3
A https://docs.aws.amazon.com/workspaces/latest/adminguide/amazon-workspaces-ip-access-control-groups.html
BrijMohan08 👍 1 Selected: B
Using AWS Firewall Manager to create a web ACL rule with an IPSet containing the list of public addresses from the branch office locations and associating it with the WorkSpaces directory is the most operationally efficient solution. AWS Firewall Manager allows you to centrally manage and apply web access control lists (web ACLs) across multiple AWS resources, including WorkSpaces. This approach ensures that the access control policy is consistently applied across the WorkSpaces environment, and it can be easily updated as the company adds a new branch office location in the next 6 months.
leliodesouza 👍 1 Selected: B
According to ChatGPT: "Among these options, option B, using AWS Firewall Manager to create a web ACL rule with an IPSet, offers the most operational efficiency. It allows for centralized management of access control rules across multiple WorkSpaces and easily scales to accommodate future changes, such as adding a new branch office. Additionally, it aligns with the company's security policy by restricting access based on IP addresses. Therefore, option B is the best choice."
pangchn 👍 4 Selected: A
A https://docs.aws.amazon.com/workspaces/latest/adminguide/amazon-workspaces-ip-access-control-groups.html
AWSPro1234 👍 1 Selected: A
Correct answer is A.
ahmadraufsyahputra 👍 1
correct answer A , need to add ip public for the branch offices to restrict access from branch offices only
Dgix 👍 4 Selected: A
A is the correct answer. It is the most operationally efficient as it uses IP access control groups.
oayoade 👍 2 Selected: A
Trust me

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

WorkSpaces supports IP access control groups at the directory level, and the console guidance is explicit that users can then access WorkSpaces only from those IP addresses. This is a single configuration object in the directory, so when the new branch office opens, its public addresses are appended to the same group with no change to the WorkSpace images or the client devices.

Why the Other Options Are Wrong

B: A web ACL in AWS Firewall Manager filters HTTP and HTTPS web requests, and WorkSpaces connections are not web requests, so the web ACL does not restrict WorkSpaces access. C: Restricted access in WorkSpaces means users cannot access the WorkSpace when the client device is unmanaged; it does not provide IP-based restriction, and certificate management is unrelated to network source filtering. D: Building a Windows Firewall custom image means every new branch office requires a new image to be built, validated, and rolled out, which is the opposite of operational efficiency.

Community Comment Notes

The community voted 87 to 1 for A. The most-liked comment confirmed the AWS console text for IP access control groups and noted that a web ACL controls HTTP and HTTPS web requests, which does not apply to WorkSpaces.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide