Courseiva

DVA-C02 Development with AWS Services Practice Question

A company uses Amazon API Gateway to expose a REST API backed by AWS Lambda. The API has a resource /items with GET and POST methods. The GET method returns items from a DynamoDB table. The POST method adds an item to the table. Currently, all methods are open to the public. Security requirements mandate that only authenticated users can access the POST method, while the GET method remains public. Which THREE steps should the developer take to meet these requirements?

⚠ Common exam trap

Many candidates assume a resource policy can be used to selectively restrict methods, but resource policies apply at the API or stage level, not at the individual method level, making them unsuitable for this granular requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the Lambda authorizer only on the POST method in the API Gateway.

You can configure a Lambda authorizer at the method level in API Gateway, which allows you to selectively secure only the POST method while leaving the GET method public. This meets the requirement of restricting access to authenticated users for POST only, without affecting the public GET endpoint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure the Lambda authorizer only on the POST method in the API Gateway.

    Why this is correct

    API Gateway allows authorizers to be configured at the method level, providing fine-grained access control. By attaching the Lambda authorizer specifically to the POST method, the company ensures that only requests targeting this particular method are subjected to the custom authorization logic, while other methods remain unaffected or use different authorization mechanisms. This meets the requirement to secure only the POST method.

  • ✓

    Create a Lambda function as an authorizer that validates a JWT token from the Authorization header.

    Why this is correct

    A Lambda authorizer, also known as a custom authorizer, is an AWS Lambda function that API Gateway invokes before passing a request to the backend integration. This function can be programmed to perform custom authorization logic, such as inspecting the Authorization header for a JWT token, validating its signature and claims, and then deciding whether to allow or deny the request based on the token's validity.

  • ✓

    In the Lambda authorizer, return an IAM policy that allows execute-api:Invoke on the POST method.

    Why this is correct

    The core responsibility of a Lambda authorizer is to return an IAM policy document to API Gateway. This policy specifies which API Gateway methods the principal (identified by the token) is authorized to invoke. By constructing a policy that explicitly grants execute-api:Invoke permission only for the specific ARN of the POST method, the authorizer precisely controls access, ensuring only authorized requests proceed to the backend.

  • ✗

    Use an Amazon Cognito User Pools authorizer for the entire API.

    Why it's wrong here

    An Amazon Cognito User Pools authorizer is designed to integrate directly with Cognito User Pools for token validation, but when configured at the API level, it applies authorization to *all* methods within that API. The requirement is to secure *only* the POST method, making this option unsuitable as it would unnecessarily restrict access to other methods that do not require this specific authorization.

  • ✗

    Add a resource policy that denies public access to the POST method.

    Why it's wrong here

    An API Gateway resource policy is a JSON policy document attached to the API itself, primarily used for cross-account access or restricting access based on source IP addresses or VPC endpoints. While resource policies can define permissions, they operate at a broader API or resource path level and are not typically used for fine-grained, token-based authorization on a single method. Furthermore, simply denying public access doesn't provide a mechanism for *authorized* access via a JWT token.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on DVA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A developer is building an API using Amazon API Gateway and AWS Lambda. The API must authenticate users using a third-party OAuth 2.0 provider. Which TWO components are required to implement this authentication?

hard
  • ✓ A.The OAuth 2.0 access token in the Authorization header
  • B.Amazon CloudFront distribution for API caching
  • C.An API Gateway resource policy that invokes the Lambda authorizer
  • ✓ D.An AWS Lambda authorizer function
  • E.An Amazon Cognito user pool as the OAuth provider

Why A: Option D is correct because a Lambda authorizer (formerly a custom authorizer) is the API Gateway mechanism that lets you plug in custom authentication logic; the function receives the caller's token, validates it against the third-party OAuth 2.0 provider (e.g., by verifying the JWT signature or calling the provider's introspection endpoint), and returns an IAM policy that allows or denies the request. Option A is correct because the client must present the OAuth 2.0 access token to API Gateway, and the standard convention is to send it in the Authorization header (typically as 'Bearer <token>'), which is exactly what the Lambda authorizer reads to perform validation. Option B is not required because a CloudFront distribution is only an optional caching/edge layer and plays no role in OAuth 2.0 authentication. Option C is incorrect because resource policies control access to the API based on source IP, VPC endpoint, or AWS account/IAM principal, not by invoking a Lambda authorizer; the authorizer is attached via the API method's authorization settings. Option E is incorrect because the scenario specifies a third-party OAuth 2.0 provider, so an Amazon Cognito user pool is not needed and would instead make Cognito the identity provider.

Variation 2. A company is using Amazon API Gateway to expose a REST API. The API must authenticate requests using an external OAuth 2.0 provider. Which API Gateway feature should be used?

medium
  • A.IAM authorization
  • B.Resource policy
  • ✓ C.Lambda authorizer
  • D.Amazon Cognito User Pools

Why C: A Lambda authorizer (formerly known as a custom authorizer) allows you to implement custom authentication logic using an external OAuth 2.0 provider. The Lambda function receives the OAuth 2.0 bearer token from the request, validates it against the external provider's token introspection endpoint or by verifying the JWT signature, and returns an IAM policy that grants or denies access to the API Gateway method.

Variation 3. A developer is using Amazon API Gateway with a Lambda authorizer to control access to an API. The authorizer function needs to decode a JWT token from the request header and return an IAM policy. Which type of Lambda authorizer should be used?

medium
  • ✓ A.TOKEN authorizer with the token passed in the Authorization header.
  • B.REQUEST authorizer with the token in a custom header.
  • C.Use Amazon Cognito User Pools as the authorizer.
  • D.Use a resource policy to allow or deny access based on the JWT token.

Why A: A TOKEN authorizer is designed to receive a JWT or OAuth token in the Authorization header and pass it directly to the Lambda function for validation. The Lambda function then decodes the token and returns an IAM policy document to allow or deny the API request. This is the correct choice because the question explicitly states the token is in the request header and needs to be decoded, which matches the TOKEN authorizer's behavior of forwarding the raw token value.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.