Which of the following are correct statements with policy evaluation logic in AWS Identity
and Access Management? Choose 2 answers
A.
An explicit deny does not override an explicit allow
B.
By default, all request are allowed
C.
An explicit allow overrides default deny.
D.
An explicit allow overrides an explicit deny
E.
By default, all requests are denied
C & E
Correct answer is CE
C & E
C and E
C,E
By default, all requests are denied. (In general, requests made using the account credentials for resources in the account are always allowed.)
An explicit allow overrides this default.
An explicit deny overrides any allows.
http://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_evaluation-logic.html
C, E
C & E
C & E