Courseiva
Security →hardMultiple Select

DVA-C02 Security Practice Question

A developer is designing a serverless application using AWS Lambda and API Gateway. The application needs to authenticate users via a third-party identity provider (IdP). Which TWO services can be used to manage user authentication?

⚠ Common exam trap

Many exam-takers confuse AWS IAM (which manages AWS resource permissions) with user authentication, or they assume STS alone can authenticate users, when in fact STS only issues tokens after authentication has already occurred via another service like Cognito or an IdP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Cognito User Pools

Amazon Cognito User Pools is a fully managed identity service that provides user sign-up, sign-in, and access control for web and mobile applications. It integrates directly with third-party identity providers (IdPs) such as Facebook, Google, or SAML-based providers, making it the correct choice for managing user authentication in a serverless application with API Gateway and Lambda.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Amazon Cognito User Pools

    Why this is correct

    Amazon Cognito User Pools act as a robust, managed user directory service that handles user sign-up, sign-in, and access control for web and mobile applications. It natively supports federation with various third-party Identity Providers (IdPs) such as Google, Facebook, Apple, and enterprise SAML/OIDC providers, allowing users to authenticate using their existing social or corporate credentials. After successful authentication, Cognito issues standard JWTs (ID and Access tokens) that can be used to authorize access to API Gateway and other AWS services.

  • ✗

    AWS IAM

    Why it's wrong here

    AWS Identity and Access Management (IAM) is primarily designed to securely control access to AWS services and resources for AWS users, groups, and roles within an AWS account. While IAM can be used with identity federation to grant temporary credentials to users authenticated by external IdPs (like SAML or OIDC providers) to access AWS resources, it does not directly authenticate end-users of a serverless application against a third-party IdP. Its core function is authorization and access management *within* AWS, not application-level user authentication.

  • ✓

    AWS Lambda custom authorizer

    Why this is correct

    An AWS Lambda custom authorizer provides a highly flexible mechanism to control access to API Gateway endpoints by executing a Lambda function before invoking the target API. It allows developers to implement custom authorization logic, such as validating JWTs or opaque tokens issued by any third-party Identity Provider (IdP) like Okta or Auth0. Upon successful validation, the Lambda function returns an IAM policy that grants or denies access to the requested API resources, making it highly adaptable for diverse authentication schemes and custom business rules.

  • ✗

    AWS Security Token Service (STS)

    Why it's wrong here

    AWS Security Token Service (STS) is a web service that enables you to request temporary, limited-privilege credentials for AWS Identity and Access Management (IAM) users or for users that you authenticate (federated users). STS is used *after* a user has been authenticated by an identity provider, to exchange an identity token for temporary AWS credentials, allowing them to access AWS resources. It does not perform the initial authentication of a user against a third-party Identity Provider itself, but rather facilitates secure access to AWS resources post-authentication.

  • ✗

    AWS Secrets Manager

    Why it's wrong here

    AWS Secrets Manager is a service designed to help you protect access to your applications, services, and IT resources by securely storing and rotating credentials, API keys, and other secrets. While it can store credentials *used by* an application to authenticate with other services, it is not an identity provider and does not facilitate the authentication of end-users of a serverless application against a third-party Identity Provider. Its role is secret management and rotation, not user authentication or identity federation.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.