Courseiva
Design for New Solutions →mediumMultiple Choice

SAP-C02 Design for New Solutions Practice Question

A company is designing a new application that will use Amazon API Gateway and AWS Lambda. The application must authenticate users using an existing OpenID Connect (OIDC) identity provider. The company wants to minimize the amount of custom code required and ensure that only authenticated users can invoke the API. Which authentication method should be used?

⚠ Common exam trap

The trap here is assuming that a Lambda authorizer is required to validate JWT tokens, when API Gateway now supports native JWT authorizers for OIDC.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use API Gateway native OpenID Connect authorization with a JWT authorizer.

API Gateway native OpenID Connect authorization with a JWT authorizer allows you to validate tokens from an OIDC provider without writing custom code. It automatically validates the token's signature, issuer, and audience, and only allows authenticated users to invoke the API. This meets the requirements with minimal custom code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Lambda authorizer with a custom authorizer function that validates JWT tokens.

    Why it's wrong here

    A Lambda authorizer requires writing and maintaining custom code to validate JWT tokens, which increases complexity. While it provides flexibility, it does not minimize custom code. The requirement is to minimize custom code, so this is not the best choice.

  • ✗

    Use API Gateway resource policies to restrict access based on IP range.

    Why it's wrong here

    Resource policies restrict access based on IP addresses or VPC endpoints, not user authentication. They do not validate OIDC tokens. This method does not meet the requirement to authenticate users with an existing OIDC provider, and it does not minimize custom code for authentication.

  • ✓

    Use API Gateway native OpenID Connect authorization with a JWT authorizer.

    Why this is correct

    API Gateway supports native OpenID Connect authorization with a JWT authorizer. You can configure it to validate tokens from your OIDC provider without writing any custom code. It automatically validates the token signature, issuer, and audience. This minimizes custom code and ensures only authenticated users can invoke the API.

  • ✗

    Use Amazon Cognito user pools with an OIDC identity provider.

    Why it's wrong here

    Amazon Cognito user pools can integrate with OIDC providers, but it requires configuring a user pool and possibly custom code for federation. It also adds an additional layer of user management. While it can minimize code, it may not be the simplest method if you only need to validate tokens from an existing OIDC provider.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.