Ultimate access to all questions.
A company has multiple AWS accounts within an organization in AWS Organizations. They have deployed Amazon VPC IP Address Manager (IPAM) in their networking AWS account and are using AWS Resource Access Manager (AWS RAM) to share IPAM pools with other accounts. A top-level IPAM pool with a CIDR block of 10.0.0.0/8 has been created, and each AWS account has its own IPAM pool within this top-level pool.
A network engineer must implement a solution to ensure that users in each AWS account are unable to create new VPCs and cannot associate CIDR blocks with existing VPCs unless the CIDR block is from the account's assigned IPAM pool.
What solution will meet these requirements?