passdrill
AWS SAA-C03 · VPC & Networking · Card 022/024 medium

A company creates an interface VPC endpoint for a supported AWS service and attaches a custom endpoint policy that restricts access to a specific IAM role. A developer using that role also has an identity-based IAM policy that denies the same action. What is the net effect, and how do these policy layers relate?

  1. The endpoint policy always overrides identity-based and resource-based policies, so the action is allowed regardless of the IAM deny
  2. The endpoint policy does not override or replace identity-based or resource-based policies; it is an additional resource-based control layer, so an explicit IAM deny still blocks the action even though the endpoint policy would otherwise permit it
  3. Endpoint policies only apply to gateway endpoints, so this interface endpoint ignores the attached policy entirely
  4. Since no endpoint policy was ever explicitly required, AWS denies all access to the endpoint by default until one is attached
Next card → Shuffle