Courseiva
Security →hardMultiple Select

DVA-C02 Lambda authorizer Practice Question

A developer needs to securely expose an API running on an EC2 instance behind an Application Load Balancer. The API should only be accessible to authenticated users via a custom authorization header. Which steps should be taken? (Choose TWO.)

⚠ Common exam trap

The trap is that candidates may assume ALB can use Lambda authorizers similar to API Gateway, but ALB lacks this feature. The correct solution is to use API Gateway with a Lambda authorizer instead of relying on ALB for custom authorization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Lambda authorizer that validates the custom header

Option A is correct because a Lambda authorizer (formerly custom authorizer) is the API Gateway mechanism designed to validate a custom authorization header by running a Lambda function that returns an IAM policy allowing or denying the request. Option D is correct because Amazon API Gateway natively supports Lambda authorizers and custom authorization headers, whereas an ALB does not provide this capability, so the API must be fronted by API Gateway to enforce header-based authentication. Option B is incorrect because AWS WAF inspects HTTP requests for threats like SQL injection or XSS and cannot perform custom token/header authorization logic. Option C is incorrect because Cognito User Pools validate JWTs issued by Cognito, not arbitrary custom authorization headers. Option E is incorrect because ALBs have no native integration with Lambda authorizers; that feature exists only in API Gateway.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a Lambda authorizer that validates the custom header

    Why this is correct

    A Lambda authorizer on the Application Load Balancer inspects the custom authorization header, validates the token, and returns an IAM policy allowing or denying the request. This enforces authentication at the load balancer before traffic reaches the EC2 instance.

  • ✗

    Enable AWS WAF on the ALB to inspect the header

    Why it's wrong here

    AWS WAF inspects and filters HTTP requests against managed or custom rules, but it does not authenticate users or validate a custom authorization header's credentials. It is tempting because WAF attaches directly to an ALB, yet the stem requires identity verification, which WAF cannot perform; that is the role of an ALB authenticate action.

  • ✗

    Use Amazon Cognito User Pools to validate the header

    Why it's wrong here

    Cognito User Pools validate tokens issued through its own sign-in flows, not an arbitrary custom header, so they cannot authorise that header. They are tempting because they handle authentication, and they are correct when clients authenticate against Cognito and present its JWT.

  • ✓

    Use Amazon API Gateway instead of ALB

    Why this is correct

    API Gateway natively supports custom authorisers, validating a custom authorization header via a Lambda authoriser before requests reach the backend. An ALB listener cannot inspect or authenticate arbitrary custom headers, so this satisfies the requirement to restrict access to authenticated users only.

  • ✗

    Configure the ALB to use the Lambda authorizer

    Why it's wrong here

    ALB listener rules cannot invoke Lambda authorizers; that integration belongs to API Gateway REST/HTTP APIs, where a Lambda authorizer validates a custom header and returns an IAM policy. The stem's ALB requirement instead needs an authenticate-oidc or authenticate-cognito listener action, so this step cannot be configured here.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.