Phase Verbs / Action Phrases
| Phrase | Meaning |
|---|---|
| attach (a policy) | link a policy to a user, group, or role |
| inherit (a policy) | receive permissions from the group you belong to |
| deny / allow access | block or permit specific API calls |
| apply (a policy) | put a policy into effect for an identity |
| consist of | be made up of (structure description) |
Technical Vocabulary
| Term | Definition |
|---|---|
| IAM Policy | JSON document that defines what actions are allowed or denied on AWS resources |
| Inline policy | A policy attached directly to a single user (not to a group) |
| Version | Policy language version; almost always "2012-10-17" |
| Statement | The core block(s) of a policy; can be one or many |
| Sid (Statement ID) | Optional identifier for a specific statement within a policy |
| Effect | Either "Allow" or "Deny" — controls whether the statement permits or blocks |
| Principal | The account, user, or role the policy applies to |
| Action | The list of AWS API calls to allow or deny (e.g., ec2:Describe*) |
| Resource | The specific AWS resource(s) the action applies to (e.g., an S3 bucket ARN) |
| Condition | Optional — additional criteria that must be true for the statement to apply |
Key Concepts
How Policy Inheritance Works
- Policy attached to a group → all members of that group inherit it
- Policy attached directly to a user → that user alone gets it (inline policy)
- A user who belongs to multiple groups inherits policies from all groups
Example:
- Developers group policy → Alice, Bob, Charles
- Operations group policy → David, Edward
- Audit team policy → Charles + David (both inherit this on top of their other group policy)
IAM Policy JSON Structure
{
"Version": "2012-10-17",
"Id": "S3-Account-Permissions",
"Statement": [
{
"Sid": "1",
"Effect": "Allow",
"Principal": {
"AWS": ["arn:aws:iam::123456789012:root"]
},
"Action": ["s3:GetObject", "s3:PutObject"],
"Resource": ["arn:aws:s3:::my-bucket/*"]
}
]
}
The 5 Key Fields to Know for the Exam
| Field | Required? | Purpose |
|---|---|---|
| Effect | Yes | Allow or Deny |
| Principal | Yes (for resource-based) | Who the policy applies to |
| Action | Yes | Which API calls |
| Resource | Yes | Which AWS resource |
| Condition | No | When the policy applies |
Exam Tips
"Version": "2012-10-17"— memorize this; it’s always the same- Effect, Principal, Action, and Resource are the 4 main fields — know them cold
- Inline policies are attached to a single user (not shareable)
- A user in multiple groups gets combined permissions from all groups