AWS Certified Developer – Associate (DVA-C02)Development with AWS ServicesHard
A developer is building a web application that uses Amazon API Gateway to expose a REST API. The API needs to be secured so that only authenticated users from a specific Amazon Cognito User Pool can access certain resources. Additionally, the developer wants to perform fine-grained authorization based on user groups within the User Pool. Which API Gateway authorization mechanism should be used?
- AIAM Authorization
- BCognito User Pool Authorizer
- CResource Policies
- DLambda Authorizer (formerly Custom Authorizer)
Show answer & explanationAnswer & explanation
Correct answer: B. Cognito User Pool Authorizer
A Cognito User Pool Authorizer is specifically designed to integrate API Gateway with Amazon Cognito User Pools, handling token validation and allowing for authorization based on claims (like group membership) within the JWT provided by Cognito. This provides both authentication and fine-grained authorization.
Why the other options are wrong
- A. IAM Authorization is suitable for authenticating AWS users/roles, not for end-users from a Cognito User Pool.
- C. Resource Policies control access to the API Gateway itself but are not designed for end-user authentication and group-based authorization from a Cognito User Pool.
- D. A Lambda Authorizer offers maximum flexibility but requires writing and maintaining custom code for authentication and authorization logic, which is more complex than the managed Cognito User Pool Authorizer for this specific use case.
API Gateway Cognito User Pool Authorizer
An API Gateway authorizer type that integrates directly with Amazon Cognito User Pools to authenticate API requests and authorize access based on JWT claims (e.g., user groups).
- Validates JWTs issued by Cognito User Pools.
- Allows fine-grained authorization based on user attributes or group membership.
- Fully managed, reducing custom code overhead.
Memory trick: When 'Cognito' users 'Pool' for API access, the 'Authorizer' is the key to 'group' control.