Courseiva
Security →hardMultiple Select

DVA-C02 Security Practice Question

A developer is designing a serverless application using AWS Lambda, Amazon API Gateway, and Amazon DynamoDB. The application must authenticate users using a third-party OIDC identity provider and authorize each request. Which THREE steps should the developer take? (Choose THREE.)

⚠ Common exam trap

Watch out — candidates often confuse the role of API Gateway authorizers: candidates often pick IAM authorizer (Option C) thinking it can validate JWTs, but IAM authorizers require AWS SigV4 signing and are not designed for OIDC token validation, while the Cognito user pool authorizer is the correct choice for JWT-based federated authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an Amazon Cognito user pool with the OIDC identity provider configured.

Amazon Cognito user pools can be configured to federate with third-party OIDC identity providers. This allows the user pool to act as an intermediary that handles the OIDC token exchange, issuing its own JWT tokens after successful authentication. This is the standard approach for integrating external OIDC providers with AWS serverless applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an Amazon Cognito user pool with the OIDC identity provider configured.

    Why this is correct

    Amazon Cognito User Pools are designed to manage user identities and provide authentication for web and mobile applications. By configuring an OIDC identity provider within a Cognito User Pool, developers can enable users to authenticate through an external OIDC-compliant service. Cognito then issues its own JWTs (ID, Access, Refresh tokens) to the application, abstracting the external OIDC provider and simplifying integration for the serverless backend. This is a standard and secure pattern for federated authentication.

  • ✗

    Generate an API key and distribute it to users for authentication.

    Why it's wrong here

    API keys are primarily used by Amazon API Gateway to identify usage plans and throttle requests from client applications, not to authenticate individual users. They are typically static, lack user-specific identity information, and do not support granular authorization based on user roles or attributes. Distributing API keys directly to end-users for authentication purposes is insecure and does not provide a robust identity management solution for a serverless application.

  • ✗

    Create an IAM authorizer in API Gateway to validate the JWT token.

    Why it's wrong here

    An IAM authorizer in API Gateway is designed to validate requests signed with AWS Signature Version 4 (SigV4) using AWS Identity and Access Management (IAM) credentials. It checks for valid IAM roles or users associated with the request, not for the structure or claims of a JSON Web Token (JWT) issued by an OIDC provider or Cognito. Therefore, an IAM authorizer cannot directly validate a JWT token for user authentication in this context.

  • ✓

    In the Lambda function, parse the JWT claims from the event context to make authorization decisions.

    Why this is correct

    After a token is validated by an API Gateway authorizer (like a Cognito User Pool authorizer or a custom Lambda authorizer), the decoded JWT claims are passed to the backend Lambda function within the event context object. The Lambda function can then programmatically inspect these claims, such as user roles, groups, or custom attributes, to implement fine-grained authorization logic specific to the application's business requirements. This allows for dynamic access control based on the authenticated user's identity.

  • ✓

    Use a Cognito user pool authorizer in API Gateway to validate the token.

    Why this is correct

    An Amazon Cognito User Pool authorizer is a native integration within API Gateway that automatically validates JWTs issued by a specified Cognito User Pool. When configured, API Gateway intercepts incoming requests, verifies the signature and expiration of the provided ID or Access token, and ensures it originated from the correct user pool. This offloads token validation from the backend Lambda function, enhancing security and simplifying the application code.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.