Resource-based policies attach directly to a resource (an S3 bucket, an SQS queue, a Lambda function) and say who can access it — including principals from other AWS accounts, enabling cross-account access.
Identity-based vs resource-based
Identity-based policies attach to a user/role and say what they can do. Resource-based policies attach to the resource and say who can act on it. Resource-based policies are the clean way to grant another account access to your bucket or queue without creating IAM users for them.
Test yourself
You must grant a specific external AWS account read access to one of your S3 buckets, without creating IAM users for them. What’s the best mechanism?
- An identity-based policy in your account
- A resource-based bucket policy naming the external account
- A permission boundary
- A security group
👉 Click to reveal the answer & explanation
Correct answer: B. A resource-based (bucket) policy can name the external account’s principal to grant cross-account access directly on the resource. An identity-based policy (A) applies to your own identities; a permission boundary (C) caps permissions; security groups (D) are network controls.
Related topics
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first