What is the difference between an S3 bucket policy and an IAM policy?
Assesses fundamental understanding of AWS conventions, runtime behavior, and memory/performance considerations.
Hiring managers look for precision, avoidance of ambiguous jargon, and ability to explain trade-offs under real production conditions.
Both are JSON documents that grant permissions, but they attach to different things.
- IAM policies are attached to identities (users, groups, roles) and define what those identities can do.
- S3 bucket policies are resource-based and attached to the bucket; they define who from any account can access it.
{
"Effect": "Allow",
"Principal": {"AWS": "arn:aws:iam::111122223333:root"},
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::my-bucket/*"
}
When both apply, a request must be allowed by the identity policy and not explicitly denied by the bucket policy. Use bucket policies for cross-account access and public-read hosting, and IAM policies to control what your own principals can do. An explicit Deny in either document always wins.
Candidate Response Strategy & Interview Tips
- Start with a concise one-sentence summary: Deliver a direct, confident answer first before expanding into nuances.
- Demonstrate real-world trade-offs: Discuss where this approach excels and when you would avoid it in production systems.
- Discuss complexity & edge cases: Proactively explain time/space complexity or boundary conditions (null values, scale limits).
- Prepare for interviewer follow-ups: Technical hiring panels frequently probe deeper into concurrency, backward compatibility, or alternative libraries.