AWS SAP-C02 · Question 51 · Domain 1.2: Security Controls
An enterprise wants to enforce strict data perimeter controls. They must ensure that IAM principals in their organization can only access AWS resources from within their corporate network or their VPCs. Which TWO mechanisms should be used together? (Select TWO)
Answer options:
AWS Organizations Service Control Policies (SCPs) with aws:SourceIp conditions.
VPC Endpoints with resource policies restricting access to the Organization ID.
AWS WAF attached to all S3 buckets.
Security Groups allowing only corporate IPs.
AWS Network Firewall blocking outbound internet access.
IAM Identity Center permission sets with MFA enabled.
75 questions · hints · full answers · grading