DVA-C02 Security Practice Question
A developer is designing a serverless application using AWS Lambda and API Gateway. The application needs to authenticate users via a third-party identity provider (IdP). Which TWO services can be used to manage user authentication?
⚠ Common exam trap
Many exam-takers confuse AWS IAM (which manages AWS resource permissions) with user authentication, or they assume STS alone can authenticate users, when in fact STS only issues tokens after authentication has already occurred via another service like Cognito or an IdP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Cognito User Pools
Amazon Cognito User Pools is a fully managed identity service that provides user sign-up, sign-in, and access control for web and mobile applications. It integrates directly with third-party identity providers (IdPs) such as Facebook, Google, or SAML-based providers, making it the correct choice for managing user authentication in a serverless application with API Gateway and Lambda.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon Cognito User Pools
Why this is correct
Amazon Cognito User Pools act as a robust, managed user directory service that handles user sign-up, sign-in, and access control for web and mobile applications. It natively supports federation with various third-party Identity Providers (IdPs) such as Google, Facebook, Apple, and enterprise SAML/OIDC providers, allowing users to authenticate using their existing social or corporate credentials. After successful authentication, Cognito issues standard JWTs (ID and Access tokens) that can be used to authorize access to API Gateway and other AWS services.
- ✗
AWS IAM
Why it's wrong here
AWS Identity and Access Management (IAM) is primarily designed to securely control access to AWS services and resources for AWS users, groups, and roles within an AWS account. While IAM can be used with identity federation to grant temporary credentials to users authenticated by external IdPs (like SAML or OIDC providers) to access AWS resources, it does not directly authenticate end-users of a serverless application against a third-party IdP. Its core function is authorization and access management *within* AWS, not application-level user authentication.
- ✓
AWS Lambda custom authorizer
Why this is correct
An AWS Lambda custom authorizer provides a highly flexible mechanism to control access to API Gateway endpoints by executing a Lambda function before invoking the target API. It allows developers to implement custom authorization logic, such as validating JWTs or opaque tokens issued by any third-party Identity Provider (IdP) like Okta or Auth0. Upon successful validation, the Lambda function returns an IAM policy that grants or denies access to the requested API resources, making it highly adaptable for diverse authentication schemes and custom business rules.
- ✗
AWS Security Token Service (STS)
Why it's wrong here
AWS Security Token Service (STS) is a web service that enables you to request temporary, limited-privilege credentials for AWS Identity and Access Management (IAM) users or for users that you authenticate (federated users). STS is used *after* a user has been authenticated by an identity provider, to exchange an identity token for temporary AWS credentials, allowing them to access AWS resources. It does not perform the initial authentication of a user against a third-party Identity Provider itself, but rather facilitates secure access to AWS resources post-authentication.
- ✗
AWS Secrets Manager
Why it's wrong here
AWS Secrets Manager is a service designed to help you protect access to your applications, services, and IT resources by securely storing and rotating credentials, API keys, and other secrets. While it can store credentials *used by* an application to authenticate with other services, it is not an identity provider and does not facilitate the authentication of end-users of a serverless application against a third-party Identity Provider. Its role is secret management and rotation, not user authentication or identity federation.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.