AWS Certified Developer – Associate (DVA-C02)SecurityHard

A company is migrating an on-premises application to AWS. The application uses a custom identity provider (IdP) for user authentication. The development team needs to integrate this custom IdP with AWS to allow authenticated users to assume IAM roles and access AWS resources directly (e.g., upload files to an S3 bucket). Which AWS service should be used to facilitate this federation?

  1. AAWS IAM Identity Center (Successor to AWS SSO)
  2. BAWS Directory Service
  3. CAmazon Cognito Identity Pools
  4. DAWS Single Sign-On (SSO)
Show answer & explanation

Correct answer: C. Amazon Cognito Identity Pools

Amazon Cognito Identity Pools (Federated Identities) are designed to federate users from various identity providers (including custom IdPs) to AWS. After authentication by the custom IdP, Identity Pools exchange the IdP's tokens for temporary, limited-privilege AWS credentials, allowing users to assume IAM roles and access AWS resources directly.

Why the other options are wrong

  • A. IAM Identity Center is the successor to AWS SSO and serves the same primary purpose of workforce identity, not customer-facing application identity federation with AWS resources.
  • B. AWS Directory Service is for managing directories (like Active Directory) within AWS, not for federating external, custom IdPs directly to AWS resource access.
  • D. AWS Single Sign-On (now IAM Identity Center) is primarily for managing access to multiple AWS accounts and cloud applications for *workforce* users, not typically for customer-facing applications with custom IdPs federating to AWS resources directly.

Cognito Identity Pools (Federated Identities)

Amazon Cognito Identity Pools provide temporary AWS credentials to users who have been authenticated by various identity providers (e.g., Cognito User Pools, Facebook, Google, SAML, or custom IdPs), allowing them to access AWS services.

  • Facilitates federation from external IdPs to AWS.
  • Exchanges IdP tokens for temporary AWS credentials.
  • Allows authenticated users to assume IAM roles for AWS resource access.
  • Supports both authenticated and unauthenticated (guest) access.

Memory trick: Custom IdP users need Identity Pools to get their AWS access keys.

More Security questions