AWS Certified Developer Associate DVA-C02 Practice Question
A developer must enable a mobile application to let users sign in with popular social-media identity providers and, after authentication, obtain AWS credentials so the app can invoke AWS service APIs directly. Which AWS service should the developer use to meet this requirement?
Call AWS Security Token Service (STS) directly to build federated user sessions with external platforms.
Deploy an Amazon Cognito User Pool to directly manage external authentication and access.
Implement an Amazon Cognito Identity Pool to federate with external identity providers and obtain temporary AWS credentials.
Use Amazon QuickSight for identity management and authorization of cloud-service API calls.
Amazon Cognito Identity Pools (federated identities) act as a credential broker: after the app receives an OAuth or OIDC token from a social provider such as Facebook, Google, Amazon, or Apple, the identity pool exchanges that token for temporary, limited-privilege AWS credentials through AWS STS. These credentials allow the mobile app to sign requests to services like S3 or DynamoDB. Cognito User Pools manage user directories and tokens but do not issue IAM credentials. AWS STS can issue credentials directly by calling AssumeRoleWithWebIdentity, but Cognito Identity Pools wrap this call, handle token caching, and simplify role mapping, making them the recommended managed solution for client applications. Amazon QuickSight is an analytics service and does not provide identity federation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
How does Amazon Cognito Identity Pool federate with external identity providers?
Open an interactive chat with Bash
What is the difference between Amazon Cognito Identity Pools and User Pools?
Open an interactive chat with Bash
What role does AWS Security Token Service play in Cognito Identity Pools?
Open an interactive chat with Bash
AWS Certified Developer Associate DVA-C02
Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .