Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A company has a web application behind an Application Load Balancer (ALB) in a VPC. The application needs to authenticate users using an external identity provider (IdP). The SysOps Administrator recommends using Amazon Cognito as an identity broker. Which ALB action should be configured to authenticate users before forwarding requests to the target group?

⚠ Common exam trap

Watch out — candidates often think a simple redirect action (Option C) is sufficient, but they miss that the ALB must actively participate in the token exchange and validation, which only the authenticate action provides.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An authenticate action using Amazon Cognito as the user pool.

Amazon Cognito integrates directly with Application Load Balancers via an authenticate action. When you configure an ALB rule with an authenticate action using a Cognito user pool, the ALB handles the OAuth 2.0 / OpenID Connect flow with the external IdP, obtains tokens, and only forwards authenticated requests to the target group. This eliminates the need for custom authentication logic in the application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    An authenticate action using Amazon Cognito as the user pool.

    Why this is correct

    The ALB authenticate action with Amazon Cognito as the user pool is purpose-built for this use case. When a rule has this action, ALB redirects the user to Cognito's hosted UI, performs the OAuth 2.0 authorization code flow, validates the returned tokens, and then forwards the request to the target with user claims embedded in X-AMZN-OIDC headers and a session cookie. This is the only option that both verifies the user's identity and creates an authenticated session at the load balancer layer.

  • ✗

    A fixed-response action to return a 401 status code.

    Why it's wrong here

    A fixed-response action returns a static HTTP 401 Unauthorized response with a custom or default body directly from the load balancer. It does not involve any identity provider, challenge handshake, or token verification, so the user is never given a way to authenticate. This simply blocks the request without establishing an authenticated session, and thus it cannot protect the application by enabling valid users to log in.

  • ✗

    A redirect action to the IdP login page.

    Why it's wrong here

    A redirect action can send the browser to an IdP login page, but it is a one-way routing instruction only. The ALB does not process the IdP callback, exchange authorization codes, issue or verify session tokens, or propagate user claims to the backend. Even if the user successfully logs in at the IdP, the ALB has no mechanism to confirm that login or create an authenticated forwarding context, so the integration is incomplete.

  • ✗

    A forward action to the target group.

    Why it's wrong here

    A forward action routes traffic to the registered targets in the target group with no authentication step at all. It does not invoke Cognito, return a challenge, or inspect any identity tokens before passing the request to the application. This leaves the backend to implement its own authentication and does not satisfy the requirement for ALB-level user authentication.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.