nerdexam
Amazon

DOP-C02 · Question #224

A company's organization in AWS Organizations has a single OU. The company runs Amazon EC2 instances in the OU accounts. The company needs to limit the use of each EC2 instance's credentials to the sp

The correct answer is B. Create an SCP that checks whether the values of the aws:EC2InstanceSourceVPC and. https://aws.amazon.com/fr/blogs/security/how-to-use-policies-to-restrict-where-ec2-instance- credentials-can-be-used-from/

Submitted by ahmad_uae· Mar 6, 2026Security and Compliance

Question

A company's organization in AWS Organizations has a single OU. The company runs Amazon EC2 instances in the OU accounts. The company needs to limit the use of each EC2 instance's credentials to the specific EC2 instance that the credential is assigned to. A DevOps engineer must configure security for the EC2 instances. Which solution will meet these requirements?

Options

  • ACreate an SCP that specifies the VPC CIDR block. Configure the SCP to check whether the value
  • BCreate an SCP that checks whether the values of the aws:EC2InstanceSourceVPC and
  • CCreate an SCP that includes a list of acceptable VPC values and checks whether the value of the
  • DCreate an SCP that checks whether the values of the aws:EC2InstanceSourceVPC and

How the community answered

(35 responses)
  • A
    20% (7)
  • B
    63% (22)
  • C
    11% (4)
  • D
    6% (2)

Explanation

https://aws.amazon.com/fr/blogs/security/how-to-use-policies-to-restrict-where-ec2-instance- credentials-can-be-used-from/

Topics

#AWS Organizations SCPs#IAM instance profiles#EC2 security#IAM policy conditions

Community Discussion

No community discussion yet for this question.

Full DOP-C02 Practice