AWS Certified Developer – Associate (DVA-C02)SecurityMedium
A developer is building a RESTful API using Amazon API Gateway. The API needs to allow authenticated users from an Amazon Cognito User Pool to access specific API resources. The developer wants a solution that natively integrates with API Gateway and automatically manages token validation. Which authorizer type should the developer configure for the API Gateway methods?
- AIAM Authorizer
- BAWS Lambda Authorizer
- CClient Certificate Authorizer
- DAmazon Cognito User Pool Authorizer
Show answer & explanationAnswer & explanation
Correct answer: D. Amazon Cognito User Pool Authorizer
An Amazon Cognito User Pool Authorizer natively integrates with API Gateway to validate JSON Web Tokens (JWTs) issued by a Cognito User Pool, providing automatic token validation and authorization for API requests.
Why the other options are wrong
- A. An IAM Authorizer uses AWS IAM roles and policies for authorization, which is suitable for AWS users/roles but not for external users authenticated via Cognito User Pools.
- B. A Lambda Authorizer is custom and requires writing code to validate tokens, which is more involved than the native Cognito User Pool integration.
- C. A Client Certificate Authorizer uses mutual TLS (mTLS) for authentication, which is for client certificate validation, not for authenticating users from a Cognito User Pool.
API Gateway Cognito User Pool Authorizer
An Amazon Cognito User Pool Authorizer is an API Gateway feature that allows native integration with a Cognito User Pool to authorize API requests. It validates JWTs from Cognito and grants access based on user pool membership.
- Natively integrates with API Gateway.
- Validates JWTs from Cognito User Pools.
- Manages token validation automatically.
- Authorizes access to API resources.
Memory trick: Cognito users unlock API Gateway with their native authorizer key.