- Home
- All questions
- Question 22
AWS Certified Solutions Architect study material · question 22 of 500
A member account reaches a resource that has no resource-based policy. Which policies must all allow the action?
Show the answer
Answer: C. The identity-based policy, the SCP and the RCP
With no resource-based policy in play the effective permissions are the intersection of the identity policy, the SCP and the RCP.
Source: Policy evaluation logic (Amazon Web Services) — Evaluating identity-based policies with AWS Organizations SCPs or RCPs