DVA-C02 Development with AWS Services Practice Question
A developer is building a RESTful API using AWS Lambda and Amazon API Gateway. The API will be accessed by external customers. The developer needs to implement authentication and authorization. Which THREE steps should the developer take to secure the API? (Choose three.)
⚠ Common exam trap
Watch out — candidates often confuse IAM roles with user authentication, thinking that passing a role ARN in the request is valid, when in fact IAM authorization requires signed requests and is not suitable for external customer authentication without AWS credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Amazon Cognito user pools for user authentication and to generate JWT tokens.
Amazon Cognito user pools provide a fully managed service for user authentication, allowing users to sign in and receive JSON Web Tokens (JWT). These tokens can then be used to authorize API requests, integrating directly with API Gateway as a built-in authorizer to secure the RESTful API.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use Amazon Cognito user pools for user authentication and to generate JWT tokens.
Why this is correct
Amazon Cognito User Pools are a fully managed service designed for user directory management, sign-up, and sign-in. They authenticate users and issue JSON Web Tokens (JWTs) (ID, access, and refresh tokens) upon successful authentication. These JWTs can then be used by clients to authorize requests to an API Gateway, making Cognito a robust and scalable solution for user authentication in RESTful APIs.
- ✗
Configure the API to use AWS IAM roles for authentication by passing the role ARN in the request.
Why it's wrong here
AWS IAM roles are primarily designed for granting permissions to AWS services or trusted entities within the AWS ecosystem, enabling secure service-to-service communication or temporary access for federated users. They are not intended for direct authentication of external end-users to a public-facing RESTful API, as requiring users to pass a role ARN directly would expose sensitive internal AWS credentials and complicate user management significantly.
- ✓
Create a Lambda authorizer that validates a JWT token from a third-party identity provider.
Why this is correct
A Lambda authorizer (formerly custom authorizer) is an AWS Lambda function that API Gateway invokes to authorize requests before passing them to the backend integration. This approach allows developers to implement custom authorization logic, such as validating JWT tokens issued by any third-party identity provider (e.g., Auth0, Okta, Google Sign-In) or even proprietary authentication systems, returning an IAM policy to permit or deny access.
- ✓
Enable Amazon Cognito as an authorizer in the API Gateway method request settings.
Why this is correct
API Gateway offers native integration with Amazon Cognito User Pools as a direct authorizer type. By configuring a method to use a Cognito User Pool authorizer, API Gateway automatically validates the JWT access token provided in the Authorization header against the specified User Pool. This eliminates the need for a separate Lambda function for authorization when using Cognito, simplifying the architecture and reducing operational overhead.
- ✗
Attach a resource policy to the API Gateway that allows only specific IAM users.
Why it's wrong here
An API Gateway resource policy is used to control access to an API from specific AWS accounts, VPCs, or IP ranges, acting as a high-level access control mechanism for the API itself. While it can reference IAM principals, it's not designed for fine-grained authentication of individual IAM users making requests to a RESTful API's methods. Its primary purpose is to define network-level or cross-account access boundaries, not per-user authentication.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.