AWS Certified Developer – Associate (DVA-C02)SecurityHard

A global company is deploying a new web application that needs to authenticate users from various identity providers, including corporate directories (via SAML) and social media accounts (e.g., Google, Apple). The application must then grant these authenticated users temporary, federated access to specific AWS resources. What is the MOST suitable AWS service to manage both authentication from these diverse sources and authorization to AWS resources?

  1. AAWS Directory Service integrated with IAM roles
  2. BAWS IAM Identity Center (SSO)
  3. CAmazon Cognito User Pools combined with Amazon Cognito Identity Pools (Federated Identities)
  4. DAmazon API Gateway with custom Lambda authorizers
Show answer & explanation

Correct answer: C. Amazon Cognito User Pools combined with Amazon Cognito Identity Pools (Federated Identities)

Amazon Cognito User Pools provide a managed user directory that can integrate with various identity providers, including SAML for corporate directories and social providers. Amazon Cognito Identity Pools then take the authenticated user and exchange their identity for temporary, limited-privilege AWS credentials, allowing federated access to AWS resources.

Why the other options are wrong

  • A. AWS Directory Service is for integrating with Microsoft Active Directory or creating a managed directory, not directly for social logins or federating consumer users to AWS resources in the same manner as Cognito.
  • B. AWS IAM Identity Center (SSO) is primarily for managing workforce access to AWS accounts and business applications, not for consumer-facing web application authentication with social providers.
  • D. API Gateway with Lambda authorizers is for authorizing access to API endpoints, not for managing diverse identity providers and granting broad federated access to multiple AWS services directly from the client.

Cognito for Enterprise & Social Federation

Amazon Cognito User Pools manage user authentication for web and mobile apps, supporting SAML for enterprise and social IDPs. Amazon Cognito Identity Pools provide federated access to AWS resources for these authenticated users.

  • User Pools support SAML, OpenID Connect, social IDPs.
  • Identity Pools provide temporary AWS credentials.
  • Ideal for consumer-facing applications with diverse user populations.

Memory trick: Cognito Unites Users and Identity for Global Access.

More Security questions