AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementMedium
A company is using AWS Cognito User Pools for customer authentication in their mobile application. They want to integrate with another backend service that requires temporary, fine-grained access to AWS resources (e.g., uploading files to a specific S3 bucket). The integration needs to be secure and minimize the exposure of long-term credentials. Which service should be used to provide these temporary AWS credentials to the authenticated Cognito users?
- AAWS Security Token Service (STS) `AssumeRole` API call directly from the mobile app.
- BAn Amazon Cognito Identity Pool (Federated Identities).
- CAWS IAM users with programmatically generated access keys.
- DAWS IAM Identity Center (formerly AWS SSO)
Show answer & explanationAnswer & explanation
Correct answer: B. An Amazon Cognito Identity Pool (Federated Identities).
Amazon Cognito Identity Pools (Federated Identities) are specifically designed to provide temporary AWS credentials to users authenticated through various identity providers, including Cognito User Pools. After a user authenticates with a User Pool, the Identity Pool exchanges the User Pool token for temporary, role-based AWS credentials, allowing the mobile application to securely access AWS resources.
Why the other options are wrong
- A. While `AssumeRole` is the underlying mechanism, directly calling STS from a mobile app after Cognito authentication would bypass the purpose of Identity Pools, which simplify this process and manage the complex trust relationships and role mapping. Identity Pools abstract this complexity.
- C. Creating IAM users and generating long-term access keys for each customer is highly insecure, unscalable, and does not provide temporary, fine-grained access. It's an anti-pattern for customer identity management.
- D. AWS IAM Identity Center is for workforce identity and single sign-on to AWS accounts and business applications, not typically for customer-facing mobile application authentication and access to AWS resources.
Amazon Cognito Identity Pools
An AWS service that provides temporary, limited-privilege AWS credentials to users who have been authenticated by an identity provider, enabling them to access AWS resources.
- Also known as Federated Identities.
- Integrates with Cognito User Pools, social identity providers (Google, Facebook), and SAML.
- Exchanges identity tokens for temporary AWS credentials.
- Allows authenticated users to access AWS resources using IAM roles.
Memory trick: User Pool + Identity Pool = Customer Access cool.