Which IAM policy evaluation logic applies when a resource-based policy grants access but an identity-based policy is silent on the action?
-
A
Access is denied by default
-
B
Access is granted because resource-based policies take precedence
-
C
Access is granted only if an explicit Allow exists in both policies
-
D
Access is denied unless an SCP allows it