Service Comparison
Identity Policy vs Resource Policy
Both can grant access, but they attach to different sides of the authorization decision.
What They Have in Common
Each option can solve part of the scenario. The exam expects you to choose the one that satisfies the stated constraints with the right operational burden, security boundary, availability model, and cost behavior.
Key Differences
| Option | Primary model | Best use | Security | Availability | Operations and cost |
|---|---|---|---|---|---|
| Identity policy | Attached to user, group, or role | What this principal can do | Managed with IAM identity | ||
| Resource policy | Attached to resource | Who can access this resource, including cross-account | Common on S3, KMS, SQS, SNS, Lambda |
Typical Exam Clues
Practice After Studying
Return to the certification guide that includes this comparison and launch domain training from there.
Sources and Review Metadata
This independent training application is not affiliated with or endorsed by Amazon Web Services. AWS, Amazon Web Services, and AWS certification names are trademarks of Amazon.com, Inc. or its affiliates.