What happens when both an AWS Identity-Based Policy and a Resource-Based Policy exist for the same action, and neither has an explicit Deny?
-
A
The identity-based policy always wins
-
B
Access is denied by default unless at least one policy allows it
-
C
Access is granted if either policy allows it
-
D
The resource-based policy always takes precedence