Courseiva
Security →hardMultiple Choice

DVA-C02 Security Practice Question

A developer is building a serverless application using API Gateway and Lambda. The API must be accessed only by authenticated users from a specific AWS Cognito User Pool. Which method should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a Cognito Authorizer on the API Gateway method.

API Gateway can use a Cognito Authorizer to validate tokens from a specific user pool.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a Lambda authorizer that checks the token against Cognito.

    Why it's wrong here

    A custom Lambda authorizer can be written to manually decode and validate a Cognito-issued JWT against the user pool's public signing keys, and this approach does work, but it requires the developer to implement token parsing, signature verification, and expiration checks by hand, duplicating logic that API Gateway's built-in Cognito authorizer already provides natively with far less code and maintenance.

  • ✗

    Use an IAM authorizer with a policy that allows only Cognito roles.

    Why it's wrong here

    An IAM authorizer validates AWS Signature Version 4 signed requests using IAM credentials, roles, or Cognito identity pool temporary AWS credentials; it does not natively validate Cognito user pool ID or access tokens, so a request carrying a Cognito user pool JWT would be rejected because it isn't a SigV4-signed request at all.

  • ✗

    Use a resource policy on API Gateway to restrict by source IP.

    Why it's wrong here

    A resource policy that restricts access by source IP address controls where requests can originate from at the network level, but it performs no validation of user identity or credentials whatsoever, so any client from an allowed IP range could call the API without ever proving they are an authenticated Cognito user.

  • ✓

    Configure a Cognito Authorizer on the API Gateway method.

    Why this is correct

    Configuring a Cognito user pool authorizer directly on the API Gateway method tells API Gateway to automatically validate the Authorization header's JWT against the specified user pool's public keys and required scopes before invoking the Lambda backend, requiring zero custom authorization code and rejecting any request lacking a valid token issued by that pool.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.