AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementEasy
A company is deploying a new web application that requires user authentication. The application needs to support both traditional username/password authentication and social identity providers like Google and Facebook. User profiles, including custom attributes, must be stored and managed securely. Which AWS service is best suited to handle these authentication and user management requirements?
- AAWS Directory Service for Microsoft Active Directory
- BAmazon Cognito User Pools
- CAWS Organizations
- DAWS IAM Identity Center (formerly AWS SSO)
Show answer & explanationAnswer & explanation
Correct answer: B. Amazon Cognito User Pools
Amazon Cognito User Pools is designed for customer-facing applications, providing user directories that support traditional username/password authentication, social identity providers (Google, Facebook), and custom attributes, making it ideal for the described web application.
Why the other options are wrong
- A. AWS Directory Service is for enterprise directories like Microsoft AD, primarily for corporate IT environments, not public web applications.
- C. AWS Organizations is used for managing multiple AWS accounts and does not provide user authentication or profile management for applications.
- D. AWS IAM Identity Center is for workforce users accessing AWS accounts and business applications, not for customer-facing application users.
Amazon Cognito User Pools
A managed user directory service for customer-facing web and mobile applications, supporting various authentication methods.
- Supports username/password, social logins (Google, Facebook, Apple), and SAML/OIDC identity providers.
- Provides user profiles with custom attributes.
- Integrates with Amazon Cognito Identity Pools for AWS resource access.
Memory trick: Think of Cognito as the 'front desk' for your app's users, handling their IDs and sign-ins.