AWS Certified Developer – Associate (DVA-C02)Development with AWS ServicesMedium

A developer is creating a mobile application that requires users to authenticate using their social media accounts (e.g., Facebook, Google) and also supports traditional email/password sign-up. The application needs to securely manage user profiles and provide temporary, limited-privilege access to AWS resources (e.g., S3 for user content). Which AWS service is the most suitable for managing user authentication, authorization, and identity federation?

  1. AAmazon Cognito
  2. BAWS IAM
  3. CAWS Organizations
  4. DAWS Directory Service
Show answer & explanation

Correct answer: A. Amazon Cognito

Amazon Cognito is a fully managed service that provides user sign-up, sign-in, and access control for mobile and web applications. It supports social identity providers, traditional user pools, and can federate identities to AWS IAM for temporary, limited-privilege access to AWS resources.

Why the other options are wrong

  • B. AWS IAM is for managing users and permissions within an AWS account, not for managing external users of a mobile/web application or integrating with social identity providers.
  • C. AWS Organizations is for managing multiple AWS accounts, not for application user authentication.
  • D. AWS Directory Service provides managed Microsoft Active Directory or Samba-compatible directories, primarily for enterprise users and applications, not for public-facing mobile/web application users with social logins.

Amazon Cognito

A service that provides authentication, authorization, and user management for your web and mobile apps.

  • Supports social identity providers (Facebook, Google, Apple).
  • Offers user pools for traditional email/password sign-up.
  • Integrates with AWS IAM for temporary access to AWS resources.

Memory trick: Cognito handles all users, from social to custom.

More Development with AWS Services questions