AWS Certified Developer – Associate (DVA-C02)SecurityMedium

A developer is building a RESTful API using Amazon API Gateway. The API needs to allow authenticated users from an Amazon Cognito User Pool to access specific API resources. The developer wants a solution that natively integrates with API Gateway and automatically manages token validation. Which authorizer type should the developer configure for the API Gateway methods?

  1. AIAM Authorizer
  2. BAWS Lambda Authorizer
  3. CClient Certificate Authorizer
  4. DAmazon Cognito User Pool Authorizer
Show answer & explanation

Correct answer: D. Amazon Cognito User Pool Authorizer

An Amazon Cognito User Pool Authorizer natively integrates with API Gateway to validate JSON Web Tokens (JWTs) issued by a Cognito User Pool, providing automatic token validation and authorization for API requests.

Why the other options are wrong

  • A. An IAM Authorizer uses AWS IAM roles and policies for authorization, which is suitable for AWS users/roles but not for external users authenticated via Cognito User Pools.
  • B. A Lambda Authorizer is custom and requires writing code to validate tokens, which is more involved than the native Cognito User Pool integration.
  • C. A Client Certificate Authorizer uses mutual TLS (mTLS) for authentication, which is for client certificate validation, not for authenticating users from a Cognito User Pool.

API Gateway Cognito User Pool Authorizer

An Amazon Cognito User Pool Authorizer is an API Gateway feature that allows native integration with a Cognito User Pool to authorize API requests. It validates JWTs from Cognito and grants access based on user pool membership.

  • Natively integrates with API Gateway.
  • Validates JWTs from Cognito User Pools.
  • Manages token validation automatically.
  • Authorizes access to API resources.

Memory trick: Cognito users unlock API Gateway with their native authorizer key.

More Security questions