Courseiva
Security →mediumMultiple Choice

DVA-C02 Security Practice Question

A company is using Amazon Cognito for user authentication. The developers need to add multi-factor authentication (MFA) for security. Which Cognito feature should be enabled?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cognito User Pools with MFA configuration

Amazon Cognito User Pools support multi-factor authentication (MFA) configurations, including SMS and TOTP. Option A is incorrect because Cognito Sync is used for synchronizing user data across devices, not for authentication or MFA. Option C is incorrect because Developer Authenticated Identities is a feature for custom authentication flows, not directly for enabling MFA. Option D is incorrect because Cognito Identity Pools provide federated identities for accessing AWS resources, but MFA is configured at the User Pool level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cognito Sync

    Why it's wrong here

    Cognito Sync is a deprecated feature that synchronized application datasets and user preferences across a user's multiple devices using a key-value store tied to identity pools; it has nothing to do with authenticating users or enforcing additional verification factors like MFA.

  • ✓

    Cognito User Pools with MFA configuration

    Why this is correct

    Cognito User Pools are the identity store and authentication service in Cognito, and they include a native MFA configuration option supporting SMS text message codes or TOTP authenticator apps, which can be set to off, optional, or required per user pool, directly satisfying the requirement to add MFA.

  • ✗

    Cognito Developer Authenticated Identities

    Why it's wrong here

    Developer Authenticated Identities is an identity pool feature that lets a custom backend authentication system vouch for a user's identity to obtain temporary AWS credentials, bypassing standard Cognito sign-in entirely, so it provides no mechanism for enforcing a second authentication factor.

  • ✗

    Cognito Identity Pools

    Why it's wrong here

    Cognito Identity Pools exchange an already-authenticated identity (from a user pool, social IdP, or SAML provider) for temporary AWS credentials to access AWS resources directly; they operate downstream of authentication and have no built-in concept of MFA, which is strictly a user pool authentication feature.

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.