AWS Certified Developer – Associate (DVA-C02)Development with AWS ServicesHard

A developer is creating a mobile application that needs to authenticate users and provide them with temporary, limited-privilege AWS credentials to directly access AWS services like Amazon S3 for uploading user-generated content. The application also needs to support authentication with social identity providers (e.g., Google, Facebook). Which AWS service should the developer use to manage user identities and issue temporary AWS credentials?

  1. AAWS Single Sign-On (SSO)
  2. BAmazon Cognito User Pools
  3. CAmazon Cognito Identity Pools (Federated Identities)
  4. DAWS Identity and Access Management (IAM)
Show answer & explanation

Correct answer: C. Amazon Cognito Identity Pools (Federated Identities)

Amazon Cognito Identity Pools (Federated Identities) is designed to grant authenticated users (from Cognito User Pools or social identity providers) temporary, limited-privilege AWS credentials. This allows the mobile application to directly access AWS services like S3 on behalf of the user, without embedding long-lived credentials in the app.

Why the other options are wrong

  • A. AWS Single Sign-On (SSO) is for centralized access to multiple AWS accounts and business applications, primarily for enterprise users, not for consumer-facing mobile application user authentication and temporary AWS credential issuance.
  • B. Amazon Cognito User Pools is an identity directory for signing up and signing in users. It handles authentication but does not *directly* issue temporary AWS credentials for accessing other AWS services. It typically integrates with Identity Pools for this purpose.
  • D. IAM manages users, groups, roles, and policies within AWS, but it doesn't provide user authentication for mobile apps or directly issue temporary credentials to end-users based on social logins.

Amazon Cognito Identity Pools

Amazon Cognito Identity Pools (Federated Identities) enable you to grant your users (authenticated by User Pools or third-party identity providers) temporary, limited-privilege AWS credentials to access AWS resources directly, such as Amazon S3 or DynamoDB.

  • Authorizes users to access AWS services.
  • Provides temporary, limited-privilege AWS credentials.
  • Integrates with Cognito User Pools and social IDPs (Google, Facebook).
  • Supports unauthenticated access for guest users.
  • Ideal for mobile and web applications needing direct AWS resource access.

Memory trick: Identity 'Pools' 'Provide' 'Permissions' for 'Private' access.

More Development with AWS Services questions