Service Comparison

Identity Policy vs Resource Policy

Both can grant access, but they attach to different sides of the authorization decision.

What They Have in Common

Each option can solve part of the scenario. The exam expects you to choose the one that satisfies the stated constraints with the right operational burden, security boundary, availability model, and cost behavior.

Key Differences

OptionPrimary modelBest useSecurityAvailabilityOperations and cost
Identity policyAttached to user, group, or roleWhat this principal can doManaged with IAM identityDepends on target service and resource availabilityCentralize and reuse; evaluate with explicit denies
Resource policyAttached to resourceWho can access this resource, including cross-accountCommon on S3, KMS, SQS, SNS, LambdaResource remains governed by its service availabilityUseful for cross-account access; scope principals and conditions

Typical Exam Clues

Practice After Studying

Return to the certification guide that includes this comparison and launch domain training from there.

Sources and Review Metadata