Enable IAM authorization on the API methods and require SigV4-signed requests from the interface VPC endpoint

Answer Correct answer: A, E — enable IAM authorization on the API methods and require callers to sign requests with Signature Version 4.

A company groups its AWS accounts in OUs in an organization in AWS Organizations. The company has deployed a set of Amazon API Gateway APIs in one of the Organizations accounts. The APIs are bound to the account's VPC and have no existing authentication mechanism. Only principals in a specific OU can have permissions to invoke the APIs. The company applies the following policy to the API Gateway interface VPC endpoint: The company also updates the API Gateway resource policies to deny invocations that do not come through the interface VPC endpoint. After the updates, the following error message appears during attempts to use the interface VPC endpoint URL to invoke an API: "User: anonymous is not authorized." Which combination of steps will solve this problem? (Choose two.) - image

  1. Enable IAM authentication on all API methods by setting AWS JAM as the authorization method. Correct Answer
  2. Create a token-based AWS Lambda authorizer that passes the caller's identity in a bearer token.
  3. Create a request parameter-based AWS Lambda authorizer that passes the caller's identity in a combination of headers, query string parameters, stage variables, and $cortext variables.
  4. Use Amazon Cognito user pools as the authorizer to control access to the API.
  5. Verify the identity of the requester by using Signature Version 4 to sign client requests by using AWS credentials. Correct Answer

Community Votes

AE
100%

100% of anonymous learners picked answer AE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The anonymous error means the request carries no AWS credentials, so the fix is to require IAM authorization on the methods so API Gateway evaluates the caller's identity (A) and to have clients sign requests with SigV4, which is how IAM authentication is satisfied when using an interface VPC endpoint (E). Options B, C, and D are token- or request-parameter-based authorizers designed for external/public callers, whereas callers inside the VPC are AWS principals and already hold AWS identities. Note the question's option A contains a typo for AWS IAM.

The APIs are private behind an interface VPC endpoint, and after the resource policies were changed to allow only endpoint-sourced requests, invocations fail with User: anonymous is not authorized because the methods still accept unsigned requests. Enabling IAM authorization on all API methods makes the endpoint recognize the caller's AWS identity, and requiring callers to sign requests with Signature Version 4 supplies that identity, resolving the anonymous caller while the VPC endpoint resource policy continues to enforce the OU restriction.

Creating a token-based Lambda authorizer (B) or a request parameter-based Lambda authorizer (C) — these are custom authorizer mechanisms for external clients, but requests arriving through an interface VPC endpoint come from AWS principals inside the VPC, so youonebe's observation applies: there is no need to mint bearer tokens or parse headers for internal callers. Using a Cognito user pool as the authorizer (D) adds a user pool to a private, already-authenticated path and does not resolve the anonymous principal.

Community Discussion (7 comments)

jamesf 👍 5 Selected: AE
Hope is Typo for the Option A, AWS JAM = AWS IAM Option A. Enable IAM authentication on all API methods by setting AWS IAM as the authorization method. - This ensures that all requests to the API must be authenticated using IAM credentials, directly addressing the anonymous access issue. Option E. Verify the identity of the requester by using Signature Version 4 to sign client requests by using AWS credentials. - By using AWS Signature Version 4, requests are authenticated, ensuring they are authorized according to IAM policies linked to the specific Organizational Unit.
youonebe 👍 3 Selected: AE
This is for requests from Interface VPC endpoints, which means all principals are internal and have aws identities. BCD are all for external request control in general.
limelight04 👍 1 Selected: AB
Option A Enable IAM authentication on all API methods: Set AWS IAM as the authorization method for all API methods. This ensures that authentication is required for invoking the APIs1. Option B Create a token-based AWS Lambda authorizer: Implement a custom Lambda authorizer that validates bearer tokens. Pass the caller’s identity in the token to authorize API requests
GripZA 👍 4 Selected: AE
You can enable IAM authorization for HTTP API routes. When IAM authorization is enabled, clients must use Signature Version 4 (SigV4) to sign their requests with AWS credentials. API Gateway invokes your API route only if the client has execute-api permission for the route.
d9iceguy 👍 4 Selected: AE
JAM= IAM
tgv 👍 2
---> A E (assuming there's a typo in AWS JAM) If there's no typo in AWS JAM, I'd go for B & E
komorebi 👍 1
Anser:B,E

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Invocations through an interface VPC endpoint are evaluated as anonymous because the requests are not signed, so API Gateway has no AWS identity to evaluate against the resource policy. Setting the authorization method to AWS IAM on all API methods (option A, whose text contains a typo for AWS IAM) makes API Gateway evaluate the caller as an AWS principal. Requiring the client to sign requests with Signature Version 4 (E) provides that identity, so the call is no longer anonymous and the resource policy that restricts invocations to the interface endpoint can be satisfied. Because all callers reaching the private endpoint already have AWS identities, this is the appropriate mechanism.

Why the Other Options Are Wrong

B creates a token-based Lambda authorizer that passes the caller's identity in a bearer token. That is a custom authentication mechanism intended for external clients that present tokens; it is unnecessary for AWS principals inside the VPC and does not by itself populate the AWS identity API Gateway needs. C creates a request parameter-based Lambda authorizer using headers, query strings, and stage variables, which is likewise a custom external-client mechanism. D uses Amazon Cognito user pools as the authorizer, introducing a user pool into a path whose callers are already AWS identities in a private network. A and E are the correct combination.

Community Comment Notes

Community voted A,E (95). Several commenters identified that the option A text 'AWS JAM' is a typo for AWS IAM, and GripZA quoted the documentation that when IAM authorization is enabled clients must sign requests with Signature Version 4 using AWS credentials. youonebe explained that B, C, and D are controls for external requests in general, whereas interface VPC endpoint callers are internal and already have AWS identities.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide