AWS Certified Developer – Associate (DVA-C02)SecurityMedium

A developer is building a RESTful API using Amazon API Gateway. The API needs to restrict access to specific users who have authenticated through a custom identity provider. The solution must ensure that only authenticated users with valid tokens can invoke the API methods. Which API Gateway authorizer type should be implemented?

  1. ALambda Authorizer (formerly Custom Authorizer)
  2. BResource Policy
  3. CIAM Authorizer
  4. DCognito User Pool Authorizer
Show answer & explanation

Correct answer: A. Lambda Authorizer (formerly Custom Authorizer)

A Lambda Authorizer (Custom Authorizer) is the correct choice because it allows the developer to implement custom authentication logic using a Lambda function. This function can validate tokens from any custom identity provider and return an IAM policy to authorize access to API Gateway methods.

Why the other options are wrong

  • B. Resource Policies control access based on IP addresses, VPCs, or other conditions, not user authentication from a custom IdP.
  • C. IAM Authorizers use AWS IAM permissions, not custom identity providers.
  • D. Cognito User Pool Authorizers are specifically for authenticating users via Amazon Cognito User Pools, not a custom identity provider.

API Gateway Lambda Authorizer

An API Gateway authorizer that uses a Lambda function to control access to API methods. The Lambda function receives an authorization token, performs custom authentication, and returns an IAM policy to API Gateway.

  • Uses custom authentication logic
  • Supports any custom identity provider
  • Returns an IAM policy for authorization

Memory trick: API Gateway's bouncer checks your ID with different methods.

More Security questions