Courseiva

DVA-C02 Development with AWS Services Practice Question

A developer is building a serverless application that uses Amazon Cognito user pools for authentication and an Amazon API Gateway REST API with a Lambda authorizer. The developer needs to ensure that the Lambda authorizer can validate tokens and return an IAM policy that allows access to specific API methods. The developer also wants to cache the authorizer result to reduce latency and cost. Which TWO actions must the developer take to meet these requirements? (Choose two.)

⚠ Common exam trap

Many candidates confuse the authorizer's response requirements, assuming a boolean or an execution role with API Gateway permissions is needed, when a full IAM policy and caching configuration are what matter.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the Lambda authorizer with a token source header, such as Authorization, and set the authorizer type to TOKEN.

To use a Lambda authorizer with a token source, the authorizer must be configured with the correct token source header and type TOKEN. Enabling authorization caching with a TTL reduces repeated Lambda invocations and latency. These two configurations together satisfy the validation and caching requirements. The authorizer must return a valid IAM policy, not a boolean, and does not require apigateway:Invoke permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use an AWS Lambda function that returns a boolean value indicating whether the token is valid.

    Why it's wrong here

    Lambda authorizers must return an IAM policy document that includes principalId, policyDocument, and optionally context. Returning only a boolean does not provide the required policy structure, and API Gateway will reject the response, causing authorization failures. The authorizer must explicitly allow or deny access.

  • ✓

    Configure the Lambda authorizer with a token source header, such as Authorization, and set the authorizer type to TOKEN.

    Why this is correct

    A TOKEN authorizer expects a single identity source header, typically Authorization. Configuring the token source correctly allows API Gateway to extract the token and pass it to the Lambda authorizer. Without specifying a valid token source, the authorizer cannot retrieve the token, and requests will fail authorization.

  • ✗

    Configure the API Gateway method to use AWS_IAM authorization instead of the Lambda authorizer.

    Why it's wrong here

    Switching to AWS_IAM authorization replaces the Lambda authorizer and does not allow custom token validation or custom IAM policy generation. This contradicts the requirement to use a Lambda authorizer for token validation and policy return. AWS_IAM uses SigV4 signatures, not bearer tokens from Cognito user pools.

  • ✗

    Attach an IAM execution role to the Lambda authorizer that grants apigateway:Invoke permissions.

    Why it's wrong here

    The Lambda authorizer does not need apigateway:Invoke permissions to authorize requests. Its execution role needs permissions only for any AWS services it calls during validation, such as Cognito or DynamoDB. Granting apigateway:Invoke is unnecessary and does not affect the authorizer's ability to return a policy.

  • ✓

    Enable authorization caching on the API Gateway authorizer and specify a time-to-live (TTL) in seconds.

    Why this is correct

    API Gateway authorizer caching stores the returned IAM policy keyed by the token value, reducing Lambda invocations and latency. Setting a TTL controls how long the policy is cached. This is a required configuration to meet the caching requirement and is supported for both TOKEN and REQUEST authorizers.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.