What it is: A JSON document that defines permissions.
What it’s for:
Core structure (conceptual):
Effect: Allow or Deny
Action: what
API actions are permitted (e.g., s3:GetObject)
Resource: which resources (e.g., a bucket, a table)
Condition: optional rules (IP, MFA, tags, time)
Key ideas:
Exam cues:
Hard words:
*effect* /ɪˈfekt/: hiệu lực (Allow/Deny)
*condition* /kənˈdɪʃn/: điều kiện
*explicit* /ɪkˈsplɪsɪt/: tường minh (ghi rõ)
Child pages: