How to Implement Mobile App Authentication with Amazon Cognito User Pools?
A developer is building the authentication mechanism for a new mobile app. Users need to be able to sign up, sign in, and access secured backend AWS resources. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the distinction between Amazon Cognito User Pools (authentication/identity management) and Identity Pools (authorization/AWS resource access), a common area of confusion for AWS developers.
To implement a mobile app authentication mechanism requiring user sign-up, sign-in, and access to secured AWS resources, developers must use Amazon Cognito User Pools. User Pools provide a fully managed user directory with built-in authentication flows, while Identity Pools handle AWS resource access via temporary credentials.
Candidates often choose Option C (Identity Pool) because the question mentions accessing 'secured backend AWS resources,' which Identity Pools handle. However, Identity Pools do not provide user sign-up or sign-in functionality, which are explicitly required in the scenario.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding Amazon Cognito Components
Amazon Cognito consists of two primary components that serve distinct purposes in the authentication and authorization flow:
User Pools act as a user directory and handle authentication. They provide:
- Complete user directory management
- Built-in sign-up and sign-in flows
- Customizable security policies (password requirements, MFA)
- User account recovery options
- Social identity provider integration
- JWT token generation for authenticated users
- Grant authenticated users access to AWS resources
- Support guest (unauthenticated) access
- Map user identities to IAM roles
- Do NOT provide user registration or login UI/flows
Why Option D is Correct
The question explicitly states three requirements: 1. Sign up - User Pools provide this 2. Sign in - User Pools provide this 3. Access secured backend AWS resources - User Pools generate tokens that can be exchanged via Identity Pools for AWS credentials
Option D correctly identifies User Pools as the solution for the authentication mechanism. The app client created in the User Pool integrates directly with mobile applications using the AWS SDK.
Why Other Options Fail
Option A incorrectly uses IAM Access Analyzer, which is a security auditing tool for analyzing resource-based policies, not an authentication mechanism.
Option B suggests attaching an IAM role directly to an API Gateway endpoint, which doesn't provide user authentication flows. This approach would require all users to share the same permissions.
Option C (the most common wrong answer) focuses on Identity Pools, which handle AWS resource access but cannot perform user sign-up or sign-in. As community member Arad noted: "Identity pool does not provide user sign-up and sign-in features."
Real-World Implementation
In practice, you would typically use both User Pools and Identity Pools together: 1. User authenticates through User Pool → receives JWT token 2. JWT token is exchanged with Identity Pool → receives temporary AWS credentials 3. Temporary credentials are used to access AWS resources (S3, DynamoDB, etc.)
However, since the question focuses on the authentication mechanism (sign-up, sign-in), User Pools are the primary answer.
Official Reference
Exam Strategy
When you see 'sign-up' and 'sign-in' in authentication questions, immediately think User Pools. When you see 'temporary credentials' or 'access AWS resources,' think Identity Pools. Many questions require both working together, but focus on what the question specifically asks for.
Related Analysis
Practice All DVA-C02 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DVA-C02 Practice Test →