AWS Certified Developer – Associate (DVA-C02)SecurityMedium
A developer is creating a mobile application that needs to authenticate users using their social identity providers (e.g., Google, Facebook) and then grant them access to specific AWS resources. The developer wants to avoid managing user credentials directly within the application or in a custom database. Which AWS service combination should be used to achieve this securely and efficiently?
- AAmazon Cognito User Pools and Amazon Cognito Identity Pools.
- BAWS Organizations and AWS Control Tower.
- CAWS IAM and S3 bucket policies.
- DAWS Directory Service and AWS Single Sign-On (SSO).
Show answer & explanationAnswer & explanation
Correct answer: A. Amazon Cognito User Pools and Amazon Cognito Identity Pools.
Amazon Cognito User Pools handle user authentication, including integration with social identity providers. Amazon Cognito Identity Pools (Federated Identities) then provide temporary, limited-privilege AWS credentials to these authenticated users, allowing them to access AWS resources securely.
Why the other options are wrong
- B. AWS Organizations and Control Tower are for managing multi-account AWS environments, not for application user authentication.
- C. IAM and S3 bucket policies are for authorization, not for managing user authentication with social providers.
- D. Directory Service and SSO are for corporate directory integration and single sign-on for enterprise users, not typically for public mobile app user authentication with social providers.
Cognito User Pools & Identity Pools
Amazon Cognito User Pools provide user directory and authentication, while Identity Pools (Federated Identities) enable granting authenticated users temporary access to AWS resources.
- User Pools manage user sign-up/sign-in.
- Identity Pools federate identities to AWS.
- Together, they provide complete authN and authZ for applications.
Memory trick: User Pools authenticate, Identity Pools give AWS access.