AWS Certified Developer – Associate (DVA-C02)SecurityMedium

A developer is building a mobile application that uses Amazon API Gateway to expose a backend Lambda function. The application needs to ensure that only authenticated users from a Cognito User Pool can invoke the API Gateway endpoint. Which authorization type should the developer configure for the API Gateway method?

  1. AIAM Authorization
  2. BAPI Key Authorization
  3. CLambda Authorizer (formerly Custom Authorizer)
  4. DCognito User Pool Authorizer
Show answer & explanation

Correct answer: D. Cognito User Pool Authorizer

A Cognito User Pool Authorizer for API Gateway is specifically designed to integrate directly with Amazon Cognito User Pools. It verifies the identity and access tokens from a Cognito User Pool to authorize requests, ensuring only authenticated users can invoke the API.

Why the other options are wrong

  • A. IAM authorization uses AWS IAM roles/users, typically for AWS services or federated enterprise users, not direct Cognito User Pool authentication for mobile apps.
  • B. API Key authorization is for usage plans and throttling, not for user authentication and authorization.
  • C. A Lambda Authorizer provides custom logic for authorization, but a Cognito User Pool Authorizer is a built-in, simpler solution for direct Cognito integration.

API Gateway Cognito User Pool Authorizer

An Amazon API Gateway authorizer that integrates directly with a Cognito User Pool to authenticate and authorize API requests based on JSON Web Tokens (JWTs) issued by the User Pool.

  • Verifies identity and access tokens from Cognito User Pools.
  • Simplifies authentication for mobile/web apps.
  • Eliminates need for custom Lambda authorizer for Cognito.

Memory trick: Cognito Authorizer is for Cognito users, Lambda for custom logic, IAM for AWS roles.

More Security questions