AWS Certified Developer – Associate (DVA-C02)SecurityMedium
A developer is creating an application that needs to grant temporary, limited-privilege access to AWS resources for unauthenticated users. These users will interact with a public web application and occasionally upload files to an S3 bucket. Which AWS service should the developer use to facilitate this access model?
- AAWS Identity and Access Management (IAM)
- BAmazon Cognito Identity Pools (Federated Identities)
- CAmazon Cognito User Pools
- DAWS Organizations
Show answer & explanationAnswer & explanation
Correct answer: B. Amazon Cognito Identity Pools (Federated Identities)
Amazon Cognito Identity Pools (Federated Identities) allow you to grant temporary, limited-privilege access to AWS resources for both authenticated and unauthenticated users. This is ideal for scenarios where public web applications need to interact with AWS services like S3 without requiring a full user authentication process.
Why the other options are wrong
- A. IAM manages users, groups, roles, and policies for authenticated access, but doesn't directly handle unauthenticated temporary access for public applications.
- C. Cognito User Pools are for user authentication and managing user directories, not for granting direct AWS resource access to unauthenticated users.
- D. AWS Organizations helps manage multiple AWS accounts and is not relevant for granting temporary resource access to application users.
Amazon Cognito Identity Pools
Provides temporary AWS credentials to users, allowing them to access AWS services directly. It supports both authenticated (via User Pools or other identity providers) and unauthenticated users.
- Grants temporary AWS credentials
- Supports authenticated and unauthenticated users
- Enables direct access to AWS resources
Memory trick: Cognito Identity Pools give temporary keys to cloud resources.