Courseiva
Security →mediumMultiple Select

DVA-C02 Security Practice Question

A developer is building a web application that uses Amazon Cognito for user authentication. Which TWO actions should be taken to secure the application?

⚠ Common exam trap

Many exam-takers think disabling token expiration improves user experience, but they overlook the critical security risk of token theft and the need for short-lived tokens (e.g., 1 hour for access tokens) combined with refresh tokens to balance security and usability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable multi-factor authentication (MFA) for users.

Enabling multi-factor authentication (MFA) adds an extra layer of security beyond just a password, requiring users to provide a second factor (e.g., a one-time code from an authenticator app or SMS). This significantly reduces the risk of unauthorized access due to compromised credentials. Amazon Cognito supports MFA natively, allowing developers to enforce it for user pools.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable multi-factor authentication (MFA) for users.

    Why this is correct

    Enabling multi-factor authentication (MFA) for users significantly enhances the security posture of a web application. MFA adds a crucial second layer of verification beyond just a password, requiring users to provide something they know (their password) and something they have (like a code from an authenticator app or a hardware token). This makes it substantially more difficult for unauthorized individuals to gain access, even if they manage to compromise a user's primary credentials, aligning with robust identity and access management best practices.

  • ✗

    Disable token expiration to avoid frequent re-authentication.

    Why it's wrong here

    Disabling token expiration is a critical security vulnerability that should be avoided in any production web application. Access tokens and refresh tokens are designed with finite lifespans precisely to limit the window of opportunity for attackers if a token is compromised or stolen. While it might seem convenient to avoid frequent re-authentication, proper token rotation and expiration, often managed with refresh tokens, are essential security mechanisms to ensure ongoing user identity verification and mitigate the impact of token theft.

  • ✓

    Use HTTPS for all communication between the client and the application.

    Why this is correct

    Implementing HTTPS (Hypertext Transfer Protocol Secure) for all communication between the client and the application is a foundational security requirement. HTTPS encrypts data in transit using TLS/SSL protocols, effectively protecting sensitive information such as user credentials, personal data, and session tokens from eavesdropping and man-in-the-middle attacks. Beyond encryption, HTTPS also provides data integrity, ensuring that data is not tampered with during transmission, and authenticates the server to the client, preventing malicious server impersonation.

  • ✗

    Use IAM users for authentication instead of Cognito.

    Why it's wrong here

    Using AWS IAM users for authenticating application end-users is an incorrect and insecure architectural decision. IAM users are specifically designed for managing programmatic and console access to AWS resources by administrators, developers, or services within an AWS account, not for external customer identity management. Amazon Cognito User Pools are the appropriate AWS service for handling user registration, authentication, and account management for web and mobile applications, offering a scalable and secure identity solution tailored for application users.

  • ✗

    Store user tokens in local storage for persistence.

    Why it's wrong here

    Storing sensitive user tokens, such as JSON Web Tokens (JWTs), directly in browser local storage is a significant security risk due to its vulnerability to Cross-Site Scripting (XSS) attacks. If a malicious script is successfully injected into the web page, it can easily access and exfiltrate all data stored in local storage, including authentication tokens, leading to session hijacking. More secure alternatives include using HTTP-only cookies, which are inaccessible to client-side JavaScript, or storing tokens in memory for the duration of the session.

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.