Courseiva
Security →hardMultiple Choice

DVA-C02 Security Practice Question

A developer is deploying a serverless application using AWS Lambda and API Gateway. The application needs to authenticate users via a third-party OIDC provider. The developer wants to minimize latency and avoid managing sessions. What is the BEST approach to achieve this?

⚠ Common exam trap

The trap is confusing Cognito User Pools (authentication, OIDC federation, JWT issuance) with Cognito Identity Pools (AWS credential vending) — candidates who pick Identity Pools misunderstand that API Gateway authorization needs authentication tokens, not temporary AWS credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Amazon Cognito User Pools with the OIDC identity provider and integrate with API Gateway.

Amazon Cognito User Pools natively support OIDC identity providers as federated IdPs, and API Gateway can use a Cognito User Pool authorizer to validate the resulting JWT tokens at the edge with minimal latency and no session management. This offloads authentication to a managed service, satisfying the requirements for third-party OIDC auth, low latency, and statelessness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use Amazon Cognito User Pools with the OIDC identity provider and integrate with API Gateway.

    Why this is correct

    Amazon Cognito User Pools provide a managed user directory service that handles user registration, authentication, and account recovery. When integrated with API Gateway, User Pools can directly validate JSON Web Tokens (JWTs) issued after successful user authentication, simplifying the authorization process. This native integration offloads token validation and user management, making it an efficient and scalable solution for serverless applications without requiring custom code.

  • ✗

    Use Lambda@Edge to validate tokens at CloudFront edge locations.

    Why it's wrong here

    Lambda@Edge functions execute at CloudFront edge locations to customize content delivery, such as modifying requests or responses before they reach the origin. While technically capable of token validation, using Lambda@Edge for API Gateway authorization is an indirect approach. It would require complex routing or duplicating authorization logic, adding unnecessary latency and architectural complexity, as its primary purpose is CDN-level customization, not direct API backend authorization.

  • ✗

    Use Amazon Cognito Identity Pools with the OIDC provider.

    Why it's wrong here

    Amazon Cognito Identity Pools (federated identities) are designed to grant authenticated users temporary, limited-privilege AWS credentials to access other AWS services directly, such as S3 or DynamoDB. They do not, however, directly authorize API Gateway requests by validating user tokens. Identity Pools bridge user identities to AWS IAM roles, focusing on resource access permissions rather than authenticating the API call itself.

  • ✗

    Implement a custom Lambda authorizer in API Gateway to validate tokens.

    Why it's wrong here

    Implementing a custom Lambda authorizer involves writing and maintaining a separate Lambda function to perform token validation, including parsing JWTs, fetching public keys, and managing token caching. This approach introduces additional operational overhead, development complexity, and potential for increased latency compared to API Gateway's native integration with Cognito User Pools. While flexible, it requires the developer to manage the entire authorization logic, which is often redundant when a managed service like Cognito User Pools is available.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DVA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A developer is designing a serverless application using AWS Lambda and API Gateway. The application needs to authenticate users via a third-party identity provider (IdP). Which TWO services can be used to manage user authentication?

hard
  • ✓ A.Amazon Cognito User Pools
  • B.AWS IAM
  • ✓ C.AWS Lambda custom authorizer
  • D.AWS Security Token Service (STS)
  • E.AWS Secrets Manager

Why A: Amazon Cognito User Pools is a fully managed identity service that provides user sign-up, sign-in, and access control for web and mobile applications. It integrates directly with third-party identity providers (IdPs) such as Facebook, Google, or SAML-based providers, making it the correct choice for managing user authentication in a serverless application with API Gateway and Lambda.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.