AWS Certified Developer – Associate (DVA-C02)SecurityEasy
A developer is building a web application that uses Amazon API Gateway to expose RESTful APIs. User authentication for this application is handled by Amazon Cognito User Pools. The developer needs to secure the API Gateway endpoints so that only authenticated users from the Cognito User Pool can invoke them. Which type of API Gateway authorizer should the developer use?
- ACognito User Pool Authorizer
- BIAM Authorizer
- CLambda Authorizer
- DAPI Key Authorizer
Show answer & explanationAnswer & explanation
Correct answer: A. Cognito User Pool Authorizer
A Cognito User Pool Authorizer is specifically designed to integrate API Gateway with Amazon Cognito User Pools, allowing API endpoints to be secured based on user authentication through Cognito.
Why the other options are wrong
- B. IAM authorizers are used for AWS IAM users/roles, not for end-user authentication via Cognito User Pools.
- C. Lambda authorizers (formerly custom authorizers) can be used, but are more generic and require custom code. Cognito User Pool authorizers are purpose-built and simpler for this specific use case.
- D. API keys are for throttling and usage plans, not for user authentication and authorization.
API Gateway Cognito User Pool Authorizer
An API Gateway Cognito User Pool Authorizer integrates directly with an Amazon Cognito User Pool to authenticate API requests. It validates the identity token provided by Cognito and authorizes access to API methods.
- Built-in integration with Cognito User Pools.
- Validates identity tokens (JWTs) from Cognito.
- Simplifies securing REST APIs with Cognito authentication.
Memory trick: API Gateway's bouncer: if it's Cognito users, then Cognito's the choice.