Study. uk . com
  1. Home
  2. All questions
  3. Question 22

AWS Certified Solutions Architect study material · question 22 of 500

A member account reaches a resource that has no resource-based policy. Which policies must all allow the action?

  1. The SCP alone
  2. The identity-based policy and the resource ACL
  3. The identity-based policy, the SCP and the RCP
  4. The identity-based policy alone
Show the answer

Answer: C. The identity-based policy, the SCP and the RCP

With no resource-based policy in play the effective permissions are the intersection of the identity policy, the SCP and the RCP.

Source: Policy evaluation logic (Amazon Web Services) — Evaluating identity-based policies with AWS Organizations SCPs or RCPs

Challenge yourself on this topic → Study as cards