AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium
A mobile app development team needs a fully managed service to handle user sign-up, sign-in, and access control for their application, including support for social identity providers like Google and Facebook, without building custom authentication infrastructure. Which AWS service should they use?
- AAWS IAM Identity Center
- BAmazon Cognito
- CAWS Secrets Manager
- DAWS Directory Service
Show answer & explanationAnswer & explanation
Correct answer: B. Amazon Cognito
Amazon Cognito provides user sign-up, sign-in, and access control for web and mobile applications, including federation with social identity providers (Google, Facebook, Amazon) and SAML/OIDC providers. IAM Identity Center is designed for workforce access to AWS accounts and business applications, AWS Directory Service provides managed Microsoft Active Directory, and Secrets Manager stores application secrets rather than managing end-user identities.
Why the other options are wrong
- A. IAM Identity Center manages workforce/employee access to AWS accounts, not app end users.
- C. Secrets Manager stores secrets like DB credentials, not user identity management.
- D. Directory Service provides managed AD for enterprise directory needs, not consumer app auth.
Amazon Cognito
A managed service providing user sign-up, sign-in, and access control for web and mobile applications, including social and enterprise identity federation.
- User Pools handle sign-up/sign-in
- Identity Pools grant temporary AWS credentials to app users
- Supports Google, Facebook, Amazon, SAML, and OIDC federation
Memory trick: Cognito = 'cognizant' of your app's end users