DVA-C02 Security Practice Question
A developer is building a serverless application using an API Gateway HTTP API and Lambda. The developer needs to authenticate users with a JWT token. Which API Gateway feature should be used?
⚠ Common exam trap
The trap is that candidates often assume they need a custom Lambda Authorizer to validate JWTs, or confuse REST API authorizers with HTTP API authorizers. For HTTP APIs, a native JWT Authorizer should be used instead of a custom Lambda Authorizer to reduce latency and cost.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
JWT Authorizer
API Gateway HTTP APIs support JWT Authorizers natively. This feature allows API Gateway to validate JSON Web Tokens (JWTs) directly without invoking a Lambda function, verifying the token's signature, expiry, and issuer against a configured identity provider (such as Amazon Cognito or any OIDC-compliant provider). This is the most efficient and cost-effective way to handle JWT authentication in HTTP APIs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Lambda Authorizer
Why it's wrong here
Lambda Authorizers necessitate writing custom code to validate JWT tokens, which is not the most direct feature when API Gateway offers native, declarative validation for standard JWTs. This option is tempting because Lambda Authorizers provide extensive flexibility for bespoke authentication and authorisation requirements, such as integrating with custom identity providers, performing database lookups, or implementing complex business logic beyond simple token validation. They are the correct choice when a developer needs full programmatic control over the authorisation process.
- ✗
IAM Authorizer
Why it's wrong here
An IAM authorizer in API Gateway validates requests signed with AWS Signature Version 4, using AWS Identity and Access Management (IAM) credentials. This mechanism is designed for authenticating requests from AWS services or applications that possess valid IAM roles or user credentials, not for validating JSON Web Tokens (JWTs) issued by a third-party identity provider. Therefore, it cannot be used to authenticate an existing JWT.
- ✓
JWT Authorizer
Why this is correct
An API Gateway JWT authorizer (also known as a native OIDC/OAuth 2.0 authorizer) is specifically designed to validate JSON Web Tokens (JWTs) issued by a third-party OpenID Connect (OIDC) or OAuth 2.0 compliant identity provider. It declaratively configures the issuer URL and audience, allowing API Gateway to automatically fetch public keys, verify the token's signature, expiration, and claims without custom code. This makes it the most direct and efficient solution for authenticating existing JWTs.
- ✗
Amazon Cognito User Pools
Why it's wrong here
Amazon Cognito User Pools primarily serve as an identity provider that can issue its own JWTs for users managed within the pool. While Cognito User Pools can be configured as an authorizer for API Gateway, this setup is for validating JWTs *issued by that specific Cognito User Pool*. It is not designed to authenticate arbitrary existing JWTs issued by an external, non-Cognito identity provider, as the question implies.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.