AWS Certified SysOps Administrator – AssociateNetworking and Content DeliveryHard
An organization relies on an Application Load Balancer (ALB) to route traffic to its web application. The security team has mandated that all user sessions must be authenticated using corporate credentials before reaching the backend application. The SysOps administrator needs to configure the ALB to handle this authentication requirement seamlessly. Which ALB feature should be utilized?
- ACross-Zone Load Balancing
- BTarget Group health checks
- CListener rules with host-based routing
- DAuthentication with Identity Providers (IdPs)
Show answer & explanationAnswer & explanation
Correct answer: D. Authentication with Identity Providers (IdPs)
ALB supports native integration with various Identity Providers (IdPs) like Amazon Cognito, Microsoft Active Directory (via SAML), or OpenID Connect. This allows the ALB to handle user authentication before forwarding authenticated requests to the backend targets, meeting the security mandate.
Why the other options are wrong
- A. Cross-Zone Load Balancing distributes traffic evenly across Availability Zones, which is a high availability feature, not an authentication feature.
- B. Target Group health checks are for monitoring the health of backend instances, not for user authentication.
- C. Listener rules with host-based routing are for directing traffic to different target groups based on hostname, not for user authentication.
ALB Listener Authentication
An Application Load Balancer feature that allows it to authenticate users directly using various Identity Providers (IdPs) before forwarding requests to backend targets.
- Supports Amazon Cognito, OpenID Connect (OIDC), and SAML 2.0
- Offloads authentication logic from backend applications
- Enhances security by ensuring only authenticated requests reach the application
- Configured as part of an ALB listener rule
Memory trick: ALB Authenticates, Listens, Routes, and Balances.