DVA-C02 Security Practice Question
A developer is designing a serverless application using API Gateway, Lambda, and DynamoDB. The API must authenticate users using a JWT token. Which API Gateway feature should the developer use to validate the JWT before invoking the Lambda function?
⚠ Common exam trap
The exam often tests your ability to choose between a Cognito authorizer and a Lambda authorizer. Remember: if the JWT is from Cognito, use the Cognito user pool authorizer (no custom code needed). If the JWT is from a third-party IdP (like Auth0, Okta, or a custom server), you must use a Lambda authorizer (for REST APIs) or a JWT authorizer (for HTTP APIs).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a Lambda authorizer (custom authorizer).
A Lambda authorizer (custom authorizer) is required to validate JWTs issued by a third-party identity provider (IdP) in API Gateway REST APIs. While Amazon Cognito user pool authorizers can natively validate Cognito-issued JWTs, they cannot validate tokens from external providers. A Lambda authorizer allows you to run custom code to verify the signature, expiration, and claims of any third-party JWT before routing the request to the backend Lambda function.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use an IAM authorizer with a resource policy.
Why it's wrong here
An IAM authorizer validates requests signed with AWS Signature Version 4 (SigV4) using AWS IAM credentials, checking against IAM policies. It is designed for AWS-native authentication and authorization, not for processing or validating custom JSON Web Tokens (JWTs) issued by external identity providers. Therefore, it cannot be used to authenticate users based on arbitrary JWTs.
- ✗
Use an Amazon Cognito user pool authorizer.
Why it's wrong here
An Amazon Cognito user pool authorizer is specifically engineered to validate JWTs issued by an Amazon Cognito User Pool. It automatically verifies the token's signature, expiration, and claims against the associated Cognito User Pool configuration. While it handles JWTs, it is tightly coupled to Cognito and lacks the capability to validate custom JWTs originating from a different, external identity provider or a bespoke authentication service.
- ✓
Use a Lambda authorizer (custom authorizer).
Why this is correct
A Lambda authorizer, also known as a custom authorizer, offers the flexibility to implement bespoke authentication and authorization logic using an AWS Lambda function. This function receives the incoming request's authorization token, such as a custom JWT, and can perform any necessary validation, including signature verification, expiration checks, and claim validation against an issuer's public key or custom business rules. If the token is valid, the Lambda function returns an IAM policy allowing access to the API Gateway resources, making it ideal for validating custom JWTs from any identity provider.
- ✗
Use an API Gateway resource policy to allow only authenticated IPs.
Why it's wrong here
An API Gateway resource policy controls access to an API based on source IP addresses, AWS accounts, or specific IAM principals, acting as an access control list at the API level. It defines who can invoke the API but does not perform user authentication or validate tokens provided by clients. While it can restrict access to certain network ranges, it cannot verify a user's identity or the authenticity of a JWT, rendering it unsuitable for authenticating users based on custom tokens.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.