AWS Certified Developer – Associate (DVA-C02)Development with AWS ServicesMedium
A client is developing a mobile application that needs to authenticate users and provide them with temporary, limited-privilege access to AWS services like Amazon S3 for uploading profile pictures. The application uses a third-party identity provider (IdP) for user authentication. Which AWS service should the developer use to facilitate this authentication and authorization flow?
- AAmazon Cognito User Pools
- BAWS Directory Service
- CAWS IAM Identity Center (SSO)
- DAmazon Cognito Identity Pools
Show answer & explanationAnswer & explanation
Correct answer: D. Amazon Cognito Identity Pools
Amazon Cognito Identity Pools (Federated Identities) allow you to grant authenticated users (from external IdPs or User Pools) temporary AWS credentials to access AWS services directly, which is exactly what's needed for uploading profile pictures to S3.
Why the other options are wrong
- A. Amazon Cognito User Pools handle user sign-up, sign-in, and directory management but do not directly grant AWS service access; Identity Pools are needed for that.
- B. AWS Directory Service integrates with or hosts Microsoft Active Directory, intended for enterprise directory services, not mobile application user authentication.
- C. AWS IAM Identity Center (SSO) is for managing workforce access to multiple AWS accounts and business applications, not for end-user mobile app authentication.
Amazon Cognito Identity Pools
Amazon Cognito Identity Pools (Federated Identities) enable you to grant your users temporary, limited-privilege access to AWS resources after they authenticate with a user pool or a third-party identity provider.
- Provides temporary AWS credentials.
- Integrates with User Pools and external identity providers.
- Grants access to AWS services like S3, DynamoDB, etc.
Memory trick: Identity Pools grant 'pool' access to AWS services.