AWS Certified Developer – Associate (DVA-C02)SecurityEasy

A development team is building a new web application that uses Amazon API Gateway to expose RESTful APIs. This application needs to integrate with an existing identity provider (IdP) that supports the OpenID Connect (OIDC) standard. Which API Gateway authorizer type should the developer choose to authenticate users from this IdP?

  1. ALambda Authorizer
  2. BCognito User Pool Authorizer
  3. CIAM Authorizer
  4. DCustom Authorizer
Show answer & explanation

Correct answer: B. Cognito User Pool Authorizer

The Cognito User Pool Authorizer is specifically designed to integrate Amazon API Gateway with Amazon Cognito User Pools. Cognito User Pools, in turn, can be configured to federate with external identity providers through standards like OpenID Connect (OIDC). This provides a managed solution for authentication and authorization for API Gateway endpoints.

Why the other options are wrong

  • A. Lambda Authorizers (Custom Authorizers) allow for highly flexible, custom authentication logic, but for standard OIDC integration via Cognito, it's an unnecessary over-complication.
  • C. IAM Authorizers use AWS IAM permissions for access control, typically for AWS users or roles, not external OIDC IdPs.
  • D. Custom Authorizer is another name for Lambda Authorizer. While it could be made to work, it requires writing and maintaining custom code for OIDC integration, which Cognito User Pools handle natively.

API Gateway Cognito User Pool Authorizer

An API Gateway authorizer that integrates directly with Amazon Cognito User Pools to manage authentication for API requests, supporting various identity providers including OIDC.

  • Simplifies authentication for API Gateway.
  • Leverages Cognito User Pools for user management and federation.
  • Supports OIDC, SAML, and social identity providers through Cognito.

Memory trick: API Gateway's door needs a 'CAP' to check IDs.

More Security questions