s3 gateway has a iam policy, what happens if i explicitly deny access to a bucket though the s3 gateway policy and have a ec2 role with explicit allow to access the same bucket?

will the explicit deny override the allow like in any general IAM policy?

