AWS Certified Developer – Associate (DVA-C02)SecurityMedium
A developer is building a mobile application that uses Amazon API Gateway to expose a backend Lambda function. The application needs to ensure that only authenticated users from a Cognito User Pool can invoke the API Gateway endpoint. Which authorization type should the developer configure for the API Gateway method?
- AIAM Authorization
- BAPI Key Authorization
- CLambda Authorizer (formerly Custom Authorizer)
- DCognito User Pool Authorizer
Show answer & explanationAnswer & explanation
Correct answer: D. Cognito User Pool Authorizer
A Cognito User Pool Authorizer for API Gateway is specifically designed to integrate directly with Amazon Cognito User Pools. It verifies the identity and access tokens from a Cognito User Pool to authorize requests, ensuring only authenticated users can invoke the API.
Why the other options are wrong
- A. IAM authorization uses AWS IAM roles/users, typically for AWS services or federated enterprise users, not direct Cognito User Pool authentication for mobile apps.
- B. API Key authorization is for usage plans and throttling, not for user authentication and authorization.
- C. A Lambda Authorizer provides custom logic for authorization, but a Cognito User Pool Authorizer is a built-in, simpler solution for direct Cognito integration.
API Gateway Cognito User Pool Authorizer
An Amazon API Gateway authorizer that integrates directly with a Cognito User Pool to authenticate and authorize API requests based on JSON Web Tokens (JWTs) issued by the User Pool.
- Verifies identity and access tokens from Cognito User Pools.
- Simplifies authentication for mobile/web apps.
- Eliminates need for custom Lambda authorizer for Cognito.
Memory trick: Cognito Authorizer is for Cognito users, Lambda for custom logic, IAM for AWS roles.