AWS Certified Developer Associate DVA-C02 Practice Question

An online retail platform uses Amazon Cognito user pools to authenticate customers for its single-page web application. The front-end must invoke a serverless REST API that is deployed on Amazon API Gateway with AWS Lambda integrations. To ensure that each API request is processed only when the caller's identity is verified, how should the application convey the client's identity to the backend?

  • Require a time-based one-time password (TOTP) code with every API request

  • Assign a unique Amazon Resource Name (ARN) to each client and send the ARN in a custom header

  • Include the user's JSON Web Token (JWT) as a Bearer value in the HTTP Authorization header for each API request

  • Rely solely on HTTPS by enabling SSL/TLS for all API Gateway endpoints

AWS Certified Developer Associate DVA-C02
Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot