Attio is the agentic CRM for modern teams. It’s your always-on revenue engine: agents and workflows build pipeline, chase every buying signal, and move deals forward alongside your team. Try Attio now.

Quick heads up before we start. Every candidate I found this week was something we'd already covered here.

So instead of a repeat, here's a study tip…

The IAM rule that fails people on every AWS exam from CCP to Security Specialty

You'll see a question like this: a user has an identity-based policy that allows S3 access. Their role also has a permission boundary, or there's an SCP at the org level, or a bucket policy on the resource itself, and one of those says deny. What happens?

Deny wins. Every time. No exceptions.

AWS evaluates permissions in a fixed order, and it's shorter than people expect:

  1. Is there an explicit deny anywhere in play (identity policy, resource policy, SCP, permission boundary, session policy)? If yes, denied. Done. Nothing else matters.

  2. No explicit deny? Is there an explicit allow anywhere? If yes, allowed.

  3. Neither? Implicit deny. AWS defaults to no.

That's it. Three steps. The part people get wrong is assuming a pile of allows can outvote a single deny somewhere else. One deny statement, buried in an SCP you forgot existed, beats five allow statements stacked on top of it.

I've watched people spend 90 seconds mentally combining four different policies to work out the "net" permission. Skip that. Scan for deny first. If you find one that applies, you're done, pick that answer, move on. Only start looking for allows once you've confirmed no deny exists anywhere in the chain.

Where this actually bites people in production. SCPs. A lot of engineers only think about identity policies and resource policies, forget their organization has an SCP layered on top, then can't figure out why an IAM policy that looks completely correct still gets denied. Permission boundaries cause the same confusion. Both act as ceilings. They cap what your identity policy already allows. Neither one can grant anything new on its own.

A resource I'd actually point you to. AWS's own policy evaluation logic page has the full decision flowchart, and it's free, no login needed. Bookmark it. I still pull it up when a Terraform IAM diff isn't doing what I expected.

If you're studying for anything AWS right now, from Cloud Practitioner through Security Specialty, this single rule shows up disguised as a dozen different scenario questions. Learn the three steps once and you'll recognize the pattern every time it comes back dressed differently.

Certification prep pages for all three major clouds are worth a bookmark too if you don't have them saved already. AWS's hub is a decent starting point.

Keep Learning and Building.

If you're studying for Azure or AWS right now, Learn Cloud Academy makes two apps for exactly that. Learn Azure and Learn AWS each have 2,000+ practice questions, and every question links to the official documentation behind it. Miss one and you can read the real answer on the spot. Both are on iOS and Android, and more than 100,000 people have used them.

If you'd rather study in a browser, the same material is on learncloudacademy.com with Google Cloud to be added, and one price covers all 3 platforms.

If someone forwarded you this, the button below gets it in your inbox every Monday.