Resource-based policies attach directly to a resource (an S3 bucket, an SQS queue, a Lambda function) and say who can access it — including principals from other AWS accounts, enabling cross-account access.

Identity-based vs resource-based

Identity-based policies attach to a user/role and say what they can do. Resource-based policies attach to the resource and say who can act on it. Resource-based policies are the clean way to grant another account access to your bucket or queue without creating IAM users for them.

Test yourself

Practice question

You must grant a specific external AWS account read access to one of your S3 buckets, without creating IAM users for them. What’s the best mechanism?

  1. An identity-based policy in your account
  2. A resource-based bucket policy naming the external account
  3. A permission boundary
  4. A security group
👉 Click to reveal the answer & explanation

Correct answer: B. A resource-based (bucket) policy can name the external account’s principal to grant cross-account access directly on the resource. An identity-based policy (A) applies to your own identities; a permission boundary (C) caps permissions; security groups (D) are network controls.

Related topics

AWS IAM · Amazon S3 · AWS STS

CloudExamPro Premium

Ready to pass the AWS Solutions Architect Associate (SAA-C03)?

Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.

  • ✓  6 full-length practice exams
  • ✓  A detailed explanation for every single question
  • ✓  Realistic, scenario-based questions — not memory dumps
  • ✓  Lifetime access, kept current for 2026

Get the SAA-C03 Practice Exams →or try 25 free questions first

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access