Subdomain 1.2: Configuring IP whitelist
1.An admin is reviewing the IP Restrictions rule table before enabling the feature: Rule name | Type | CIDR range | Status Office network | Allow | 198.51.100.0/24 | enabled Corporate VPN | Allow | 203.0.113.0/24 | enabled Flagged contractor | Deny | 203.0.113.128/28 | enabled Legacy office | Allow | 192.0.2.0/24 | disabled A contractor connects from 203.0.113.130, an address inside both the Corporate VPN Allow range and the Flagged contractor Deny range. Based on this table, which rule determines the outcome for that connection?
- A.The Flagged contractor Deny rule, because a narrower Deny range nested inside a broader Allow range takes precedence for the addresses it covers.
- B.The Corporate VPN Allow rule, because Allow rules are always evaluated ahead of Deny rules regardless of how the ranges compare in size.
- C.The Legacy office rule, because a disabled rule still applies to any address that would otherwise be denied by an active Deny rule.
- D.Neither rule applies, because dbt Cloud requires an exact single-address match rather than accepting CIDR ranges for enforcement.
Show answer & explanation
Correct answer: A — The Flagged contractor Deny rule, because a narrower Deny range nested inside a broader Allow range takes precedence for the addresses it covers.
- A. This is correct: the contractor's address falls inside the narrower Flagged contractor Deny range nested within the broader Corporate VPN Allow range, and the narrower Deny rule wins for that address.
- B. This is incorrect because rule priority is based on range specificity, not rule type; a nested, more specific Deny range overrides the broader Allow range containing it.
- C. This is incorrect because a rule marked disabled in the table plays no role in evaluating the connection at all, regardless of what its CIDR range would otherwise cover.
- D. This is incorrect because dbt Cloud's IP restriction rules are defined and enforced using CIDR ranges, not single-address matching.