Courseiva

DVA-C02 Development with AWS Services Practice Question

A developer is building a RESTful API using AWS Lambda and Amazon API Gateway. The API will be accessed by external customers. The developer needs to implement authentication and authorization. Which THREE steps should the developer take to secure the API? (Choose three.)

⚠ Common exam trap

Watch out — candidates often confuse IAM roles with user authentication, thinking that passing a role ARN in the request is valid, when in fact IAM authorization requires signed requests and is not suitable for external customer authentication without AWS credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Amazon Cognito user pools for user authentication and to generate JWT tokens.

Amazon Cognito user pools provide a fully managed service for user authentication, allowing users to sign in and receive JSON Web Tokens (JWT). These tokens can then be used to authorize API requests, integrating directly with API Gateway as a built-in authorizer to secure the RESTful API.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use Amazon Cognito user pools for user authentication and to generate JWT tokens.

    Why this is correct

    Amazon Cognito User Pools are a fully managed service designed for user directory management, sign-up, and sign-in. They authenticate users and issue JSON Web Tokens (JWTs) (ID, access, and refresh tokens) upon successful authentication. These JWTs can then be used by clients to authorize requests to an API Gateway, making Cognito a robust and scalable solution for user authentication in RESTful APIs.

  • ✗

    Configure the API to use AWS IAM roles for authentication by passing the role ARN in the request.

    Why it's wrong here

    AWS IAM roles are primarily designed for granting permissions to AWS services or trusted entities within the AWS ecosystem, enabling secure service-to-service communication or temporary access for federated users. They are not intended for direct authentication of external end-users to a public-facing RESTful API, as requiring users to pass a role ARN directly would expose sensitive internal AWS credentials and complicate user management significantly.

  • ✓

    Create a Lambda authorizer that validates a JWT token from a third-party identity provider.

    Why this is correct

    A Lambda authorizer (formerly custom authorizer) is an AWS Lambda function that API Gateway invokes to authorize requests before passing them to the backend integration. This approach allows developers to implement custom authorization logic, such as validating JWT tokens issued by any third-party identity provider (e.g., Auth0, Okta, Google Sign-In) or even proprietary authentication systems, returning an IAM policy to permit or deny access.

  • ✓

    Enable Amazon Cognito as an authorizer in the API Gateway method request settings.

    Why this is correct

    API Gateway offers native integration with Amazon Cognito User Pools as a direct authorizer type. By configuring a method to use a Cognito User Pool authorizer, API Gateway automatically validates the JWT access token provided in the Authorization header against the specified User Pool. This eliminates the need for a separate Lambda function for authorization when using Cognito, simplifying the architecture and reducing operational overhead.

  • ✗

    Attach a resource policy to the API Gateway that allows only specific IAM users.

    Why it's wrong here

    An API Gateway resource policy is used to control access to an API from specific AWS accounts, VPCs, or IP ranges, acting as a high-level access control mechanism for the API itself. While it can reference IAM principals, it's not designed for fine-grained authentication of individual IAM users making requests to a RESTful API's methods. Its primary purpose is to define network-level or cross-account access boundaries, not per-user authentication.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.