DVA-C02 Lambda Authorizer Practice Question
A developer is building an API using Amazon API Gateway and AWS Lambda. The API must authenticate users using a third-party OAuth 2.0 provider. Which TWO components are required to implement this authentication?
⚠ Common exam trap
The trap is that candidates may think a resource policy is needed to invoke the Lambda authorizer, but the authorizer is configured separately via API Gateway's authorizer settings. The correct required components are the OAuth token and a Lambda authorizer function.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The OAuth 2.0 access token in the Authorization header
Option D is correct because a Lambda authorizer (formerly a custom authorizer) is the API Gateway mechanism that lets you plug in custom authentication logic; the function receives the caller's token, validates it against the third-party OAuth 2.0 provider (e.g., by verifying the JWT signature or calling the provider's introspection endpoint), and returns an IAM policy that allows or denies the request. Option A is correct because the client must present the OAuth 2.0 access token to API Gateway, and the standard convention is to send it in the Authorization header (typically as 'Bearer <token>'), which is exactly what the Lambda authorizer reads to perform validation. Option B is not required because a CloudFront distribution is only an optional caching/edge layer and plays no role in OAuth 2.0 authentication. Option C is incorrect because resource policies control access to the API based on source IP, VPC endpoint, or AWS account/IAM principal, not by invoking a Lambda authorizer; the authorizer is attached via the API method's authorization settings. Option E is incorrect because the scenario specifies a third-party OAuth 2.0 provider, so an Amazon Cognito user pool is not needed and would instead make Cognito the identity provider.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The OAuth 2.0 access token in the Authorization header
Why this is correct
Passing the third-party OAuth 2.0 access token in the Authorization header lets API Gateway validate it against the provider's JWKS endpoint via a Lambda authoriser or JWT authoriser, satisfying the requirement to authenticate users through an external OAuth 2.0 provider rather than native AWS credentials.
- ✗
Amazon CloudFront distribution for API caching
Why it's wrong here
CloudFront caches responses at edge locations; it neither validates OAuth 2.0 tokens nor invokes authorizers. The scenario needs a Lambda authorizer to validate the third-party token and an API Gateway authorizer configuration that attaches it to the API methods.
- ✗
An API Gateway resource policy that invokes the Lambda authorizer
Why it's wrong here
A resource policy controls which principals may invoke the API; it performs no token validation and cannot call a Lambda authorizer. The required components are a Lambda authorizer that validates the third-party OAuth 2.0 token and an API Gateway authorizer configuration referencing it.
- ✓
An AWS Lambda authorizer function
Why this is correct
A Lambda authorizer validates the third-party OAuth 2.0 token and returns an IAM policy, letting API Gateway enforce authorisation. It is required because API Gateway cannot natively validate arbitrary third-party OAuth tokens without custom logic.
- ✗
An Amazon Cognito user pool as the OAuth provider
Why it's wrong here
The stem specifies a third-party OAuth 2.0 provider, so a Cognito user pool would itself be the identity provider, not the external one. Cognito user pools suit scenarios where you control the user directory; here a Lambda authorizer validating the third-party token is required.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.