Courseiva
Security →mediumMultiple Choice

DVA-C02 Security Practice Question

A developer is configuring a load balancer in front of an EC2 instance running a web application. The application needs to authenticate users via an identity provider. Which AWS service should the developer use to handle authentication and authorization?

⚠ Common exam trap

DVA-C02 often tests the distinction between IAM (for AWS service access) and Cognito (for application user authentication), so candidates may incorrectly choose IAM when the question involves end-user authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Cognito

Amazon Cognito is designed to handle user authentication and authorization for web and mobile applications. It provides user pools for sign-up/sign-in and identity pools for federated identities, allowing integration with external identity providers (IdPs) like Google, Facebook, and SAML. Since the application needs to authenticate users via an identity provider, Cognito is the correct choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Identity and Access Management (IAM)

    Why it's wrong here

    AWS IAM manages authentication and fine-grained authorization for AWS principals such as IAM users, roles, and federated identities accessing AWS APIs and the console; it is not designed to authenticate external end users of a custom web application, which requires an identity service like a user pool rather than IAM's AWS-resource-centric permission model.

  • ✓

    Amazon Cognito

    Why this is correct

    Amazon Cognito provides user pools that handle sign-up, sign-in, and access control for web and mobile application users, including integration with third-party identity providers and social logins, and it issues JSON Web Tokens that a load balancer's built-in authentication action can validate before forwarding requests to the EC2 target, making it the purpose-built service for this use case.

  • ✗

    Amazon Route 53

    Why it's wrong here

    Amazon Route 53 is a highly available DNS service used to route domain names to endpoints such as load balancers or S3 websites; it has no concept of user identity, sessions, or credential validation and therefore cannot perform authentication or authorization for application users.

  • ✗

    Amazon CloudFront

    Why it's wrong here

    Amazon CloudFront is a content delivery network that caches and accelerates delivery of static and dynamic content at edge locations closer to users; while it can integrate with Lambda@Edge for custom logic, it does not natively provide user authentication or identity-provider integration on its own.

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.