What it is: The rules AWS uses to decide whether a request is allowed.
What it’s for: Predict and troubleshoot access problems.
Decision rules (high-level):
Default is implicit deny (không ghi Allow thì coi như không được).
If there is any explicit deny, the request is denied.
Otherwise, if there is at least one allow, the request is allowed.
Common exam cues:
Hard words: