You can restrict the scope of a user's permissions by specifying which two items in an IAM policy?
events and users
resources and users
resources and conditions
events and conditions