AWS Certified Developer – Associate (DVA-C02)Development with AWS ServicesMedium
A developer is creating a mobile application that requires users to authenticate using their social media accounts (e.g., Facebook, Google) and also supports traditional email/password sign-up. The application needs to securely manage user profiles and provide temporary, limited-privilege access to AWS resources (e.g., S3 for user content). Which AWS service is the most suitable for managing user authentication, authorization, and identity federation?
- AAmazon Cognito
- BAWS IAM
- CAWS Organizations
- DAWS Directory Service
Show answer & explanationAnswer & explanation
Correct answer: A. Amazon Cognito
Amazon Cognito is a fully managed service that provides user sign-up, sign-in, and access control for mobile and web applications. It supports social identity providers, traditional user pools, and can federate identities to AWS IAM for temporary, limited-privilege access to AWS resources.
Why the other options are wrong
- B. AWS IAM is for managing users and permissions within an AWS account, not for managing external users of a mobile/web application or integrating with social identity providers.
- C. AWS Organizations is for managing multiple AWS accounts, not for application user authentication.
- D. AWS Directory Service provides managed Microsoft Active Directory or Samba-compatible directories, primarily for enterprise users and applications, not for public-facing mobile/web application users with social logins.
Amazon Cognito
A service that provides authentication, authorization, and user management for your web and mobile apps.
- Supports social identity providers (Facebook, Google, Apple).
- Offers user pools for traditional email/password sign-up.
- Integrates with AWS IAM for temporary access to AWS resources.
Memory trick: Cognito handles all users, from social to custom.