Enable IAM authorization on the API methods and require SigV4-signed requests from the interface VPC endpoint
A company groups its AWS accounts in OUs in an organization in AWS Organizations. The company has deployed a set of Amazon API Gateway APIs in one of the Organizations accounts. The APIs are bound to the account's VPC and have no existing authentication mechanism. Only principals in a specific OU can have permissions to invoke the APIs. The company applies the following policy to the API Gateway interface VPC endpoint: The company also updates the API Gateway resource policies to deny invocations that do not come through the interface VPC endpoint. After the updates, the following error message appears during attempts to use the interface VPC endpoint URL to invoke an API: "User: anonymous is not authorized." Which combination of steps will solve this problem? (Choose two.) - 
Community Votes
100% of anonymous learners picked answer AE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The anonymous error means the request carries no AWS credentials, so the fix is to require IAM authorization on the methods so API Gateway evaluates the caller's identity (A) and to have clients sign requests with SigV4, which is how IAM authentication is satisfied when using an interface VPC endpoint (E). Options B, C, and D are token- or request-parameter-based authorizers designed for external/public callers, whereas callers inside the VPC are AWS principals and already hold AWS identities. Note the question's option A contains a typo for AWS IAM.
The APIs are private behind an interface VPC endpoint, and after the resource policies were changed to allow only endpoint-sourced requests, invocations fail with User: anonymous is not authorized because the methods still accept unsigned requests. Enabling IAM authorization on all API methods makes the endpoint recognize the caller's AWS identity, and requiring callers to sign requests with Signature Version 4 supplies that identity, resolving the anonymous caller while the VPC endpoint resource policy continues to enforce the OU restriction.
Creating a token-based Lambda authorizer (B) or a request parameter-based Lambda authorizer (C) — these are custom authorizer mechanisms for external clients, but requests arriving through an interface VPC endpoint come from AWS principals inside the VPC, so youonebe's observation applies: there is no need to mint bearer tokens or parse headers for internal callers. Using a Cognito user pool as the authorizer (D) adds a user pool to a private, already-authenticated path and does not resolve the anonymous principal.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Invocations through an interface VPC endpoint are evaluated as anonymous because the requests are not signed, so API Gateway has no AWS identity to evaluate against the resource policy. Setting the authorization method to AWS IAM on all API methods (option A, whose text contains a typo for AWS IAM) makes API Gateway evaluate the caller as an AWS principal. Requiring the client to sign requests with Signature Version 4 (E) provides that identity, so the call is no longer anonymous and the resource policy that restricts invocations to the interface endpoint can be satisfied. Because all callers reaching the private endpoint already have AWS identities, this is the appropriate mechanism.Why the Other Options Are Wrong
B creates a token-based Lambda authorizer that passes the caller's identity in a bearer token. That is a custom authentication mechanism intended for external clients that present tokens; it is unnecessary for AWS principals inside the VPC and does not by itself populate the AWS identity API Gateway needs. C creates a request parameter-based Lambda authorizer using headers, query strings, and stage variables, which is likewise a custom external-client mechanism. D uses Amazon Cognito user pools as the authorizer, introducing a user pool into a path whose callers are already AWS identities in a private network. A and E are the correct combination.Community Comment Notes
Community voted A,E (95). Several commenters identified that the option A text 'AWS JAM' is a typo for AWS IAM, and GripZA quoted the documentation that when IAM authorization is enabled clients must sign requests with Signature Version 4 using AWS credentials. youonebe explained that B, C, and D are controls for external requests in general, whereas interface VPC endpoint callers are internal and already have AWS identities.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →