SAA-C03 Design Secure Architectures Practice Question
A public API for a e-learning platform is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used?
⚠ Common exam trap
Many candidates confuse API keys (which only identify the caller for usage plans) with authentication mechanisms, or assume IAM authorization can validate third-party OIDC tokens, when in fact IAM authorization requires AWS credentials, not external tokens.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
JWT authorizer configured for the OpenID Connect issuer
API Gateway supports JWT authorizers that validate JSON Web Tokens (JWTs) issued by an external OpenID Connect (OIDC) provider. This allows the API to authenticate clients using standards-based tokens without managing a custom Lambda authorizer, and it directly integrates with the OIDC issuer's JWKS endpoint to verify token signatures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A VPC endpoint policy
Why it's wrong here
A VPC endpoint policy governs access to the API through a private VPC endpoint, restricting which principals and actions are allowed, but it does not validate the identity of end users calling the public endpoint. Since the API is public, users bypass VPC endpoints entirely, so the policy cannot enforce authentication or verify OIDC tokens; it is purely a network-level access control, not an identity layer.
- ✗
IAM authorization for all internet users
Why it's wrong here
IAM authorization is inappropriate for all internet users because IAM credentials are designed for AWS principals (IAM users, roles, or AWS services), not for arbitrary application users holding OIDC tokens from an external identity provider. To use IAM, each student or educator would need AWS credentials, and the client would have to sign every request with Signature Version 4—an impractical and insecure way to expose a public e-learning API. IAM also fails to integrate with the platform's existing identity provider, whereas a JWT authorizer natively trusts that provider.
- ✗
API keys only
Why it's wrong here
API keys only identify the calling application or project for usage plans, quotas, and throttling; they do not authenticate an individual user's identity or verify any claims about who they are. An API key can be extracted from a client and reused by anyone, so it offers no assurance that the caller is a legitimate student or educator with valid OIDC credentials. For public APIs, API keys are insufficient for security and must be combined with an authentication mechanism such as a JWT authorizer.
- ✓
JWT authorizer configured for the OpenID Connect issuer
Why this is correct
The JWT authorizer configured for the OpenID Connect issuer is the correct choice because it validates the JWT's signature, expiry, issuer, and audience against the OIDC provider's public keys (JWKS), requiring no custom Lambda or additional infrastructure. It integrates directly with any standards-compliant IdP—such as Auth0, Okta, or the platform's existing identity service—so users' existing login tokens are recognized. This approach authenticates every request with low latency and minimal operational overhead while supporting fine-grained scopes and claims for authorization.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.