Q8Network Security, Compliance, and Governance
A company has AWS accounts within an AWS Organizations organization. It has implemented Amazon VPC IP Address Manager (IPAM) in its networking AWS account and uses AWS Resource Access Manager (AWS RAM) to share IPAM pools with the other AWS accounts. The company created a top-level pool with the CIDR block `10.0.0.0/8`. Within that top-level pool, it created an IPAM pool for each AWS account. A network engineer must implement a solution that ensures users in each AWS account cannot create new VPCs. The solution must also stop users from associating a CIDR block with an existing VPC unless that CIDR block comes from the IPAM pool for that account. Which solution meets these requirements?
← → navigate · a answer
Community votes
Discussion · 6
B 4
The most suitable option for enforcing the policy at the point of action (creating or associating CIDR blocks) across all AWS accounts in the organization is option B. Therefore, the correct answer is:
B. Create a new SCP in Organizations. Add a condition that denies the CreateVpc and AssociateVpcCidrBlock Amazon EC2 actions if the Ipv4IpamPoolId context key value is not the ID of an IPAM pool.
B 3
Option B meets all of the requirements with least operational overhead:
It creates a new SCP in Organizations that denies the CreateVpc and AssociateVpcCidrBlock Amazon EC2 actions if the Ipv4IpamPoolId context key value is not the ID of an IPAM pool.
The SCP will prevent users from creating VPCs without the correct CIDR block.
It prevents users from associating a CIDR block with existing VPCs unless the CIDR block is from the IPAM pool for that account.
B 1
AWS Organization Service control
policy (SCP) to enforce CIDR
allocation through IPAM while
creating VPCs
• Enforce using specific IPAM pools
• Enforce specific IPAM pools to
specific OUs
1
B - This meets the requirements, although option A would as well. Only issue with option A, is the deletion of VPC's. Doesn't mention removing or reclaiming existing IP's.
B 1
Option B is the most effective and efficient solution because it proactively prevents non-compliant actions at the organization level, enforcing a strict policy that ensures VPC creation and CIDR block associations are limited to IPAM pools. By leveraging SCPs, you can maintain control over your network architecture, ensuring all resources comply with predefined security and operational guidelines.
A 1
aws config