Service Comparison
Identity Policy vs Resource Policy
Both can grant access, but they attach to different sides of the authorization decision.
What They Have in Common
Each option can solve part of the scenario. The exam expects you to choose the one that satisfies the stated constraints with the right operational burden, security boundary, availability model, and cost behavior.
Key Differences
| Option | Primary model | Best use | Security | Availability | Operations and cost |
|---|---|---|---|---|---|
| Identity policy | Attached to user, group, or role | What this principal can do | Managed with IAM identity | Depends on target service and resource availability | Centralize and reuse; evaluate with explicit denies |
| Resource policy | Attached to resource | Who can access this resource, including cross-account | Common on S3, KMS, SQS, SNS, Lambda | Resource remains governed by its service availability | Useful for cross-account access; scope principals and conditions |
Typical Exam Clues
Practice After Studying
Return to the certification guide that includes this comparison and launch domain training from there.
DJames617