Exit 23 / 40

Question 23

Domain 4: Identity and Access Management

An IAM engineer is reviewing an AWS resource-based policy that allows access only when requests come from a specific AWS account and only for certain API calls against one S3 bucket. Which policy components identify who can access the resource, what operation can be performed, and which object is being accessed?