- Home
- All questions
- Question 143
AWS Certified Solutions Architect study material · question 143 of 500
With ACLs disabled on a bucket, which policy types decide access?
Show the answer
Answer: B. IAM user policies, bucket policies, VPC endpoint policies, SCPs and RCPs
Once ACLs are off, access is decided purely by policies, which is what makes permissions simpler to audit.
Source: Security best practices for Amazon S3 (Amazon Web Services) — Disable access control lists (ACLs)