AWS Certified Developer – Associate (DVA-C02)SecurityMedium
A developer is building a RESTful API using Amazon API Gateway. The API needs to restrict access to specific users who have authenticated through a custom identity provider. The solution must ensure that only authenticated users with valid tokens can invoke the API methods. Which API Gateway authorizer type should be implemented?
- ALambda Authorizer (formerly Custom Authorizer)
- BResource Policy
- CIAM Authorizer
- DCognito User Pool Authorizer
Show answer & explanationAnswer & explanation
Correct answer: A. Lambda Authorizer (formerly Custom Authorizer)
A Lambda Authorizer (Custom Authorizer) is the correct choice because it allows the developer to implement custom authentication logic using a Lambda function. This function can validate tokens from any custom identity provider and return an IAM policy to authorize access to API Gateway methods.
Why the other options are wrong
- B. Resource Policies control access based on IP addresses, VPCs, or other conditions, not user authentication from a custom IdP.
- C. IAM Authorizers use AWS IAM permissions, not custom identity providers.
- D. Cognito User Pool Authorizers are specifically for authenticating users via Amazon Cognito User Pools, not a custom identity provider.
API Gateway Lambda Authorizer
An API Gateway authorizer that uses a Lambda function to control access to API methods. The Lambda function receives an authorization token, performs custom authentication, and returns an IAM policy to API Gateway.
- Uses custom authentication logic
- Supports any custom identity provider
- Returns an IAM policy for authorization
Memory trick: API Gateway's bouncer checks your ID with different methods.