Restrict Amazon WorkSpaces access with an IP access control group
A company wants to use Amazon WorkSpaces in combination with thin client devices to replace aging desktops. Employees use the desktops to access applications that work with Clinical trial data. Corporate security policy states that access to the applications must be restricted to only company branch office locations. The company is considering adding an additional branch office in the next 6 months. Which solution meets these requirements with the MOST operational efficiency?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
An IP access control group is a native WorkSpaces directory feature, so associating the office public IPs with the directory is a configuration change that the same team repeats when the new branch opens.
Thin client WorkSpaces must reach clinical trial applications only from company branch office locations, and a new branch office is planned within six months. The control must be centrally managed so the new location is added without rebuilding images.
Reaching for AWS Firewall Manager with a web ACL. Firewall Manager and WAF web ACLs operate on HTTP and HTTPS requests and are not applied to WorkSpaces client connections, so they cannot restrict access to a WorkSpaces directory.
Community Discussion (13 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
WorkSpaces supports IP access control groups at the directory level, and the console guidance is explicit that users can then access WorkSpaces only from those IP addresses. This is a single configuration object in the directory, so when the new branch office opens, its public addresses are appended to the same group with no change to the WorkSpace images or the client devices.Why the Other Options Are Wrong
B: A web ACL in AWS Firewall Manager filters HTTP and HTTPS web requests, and WorkSpaces connections are not web requests, so the web ACL does not restrict WorkSpaces access. C: Restricted access in WorkSpaces means users cannot access the WorkSpace when the client device is unmanaged; it does not provide IP-based restriction, and certificate management is unrelated to network source filtering. D: Building a Windows Firewall custom image means every new branch office requires a new image to be built, validated, and rolled out, which is the opposite of operational efficiency.Community Comment Notes
The community voted 87 to 1 for A. The most-liked comment confirmed the AWS console text for IP access control groups and noted that a web ACL controls HTTP and HTTPS web requests, which does not apply to WorkSpaces.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →