Put Amazon Cognito authentication with MFA in front of a Fargate application on an ALB
A company is deploying a third-party web application on AWS. The application is packaged as a Docker image. The company has deployed the Docker image as an AWS Fargate service in Amazon Elastic Container Service (Amazon ECS). An Application Load Balancer (ALB) directs traffic to the application. The company needs to give only a specific list of users the ability to access the application from the internet. The company cannot change the application and cannot integrate the application with an identity provider. All users must be authenticated through multi-factor authentication (MFA). Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
ALB supports native authentication with a Cognito user pool, so the identity check happens at the listener before traffic ever reaches the Fargate tasks, which is what allows an unmodified third-party application to sit behind an authenticated endpoint.
A third-party Docker image runs as a Fargate service behind an Application Load Balancer, and only a specific list of users may reach it from the internet. The application cannot be changed and cannot be integrated with an identity provider, and every user must authenticate with multi-factor authentication.
Attaching a resource policy to the Fargate service to require MFA. Resource policies on a compute service do not enforce end-user authentication, and IAM identities are for AWS principals such as roles and users signing API calls, not for interactive browser sessions arriving through a load balancer.
Community Discussion (10 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
An Amazon Cognito user pool holds the specific list of permitted users and can be configured to require MFA, which satisfies both the user allowlist and the multi-factor requirement. The Application Load Balancer can be configured to authenticate users against a Cognito user pool on its listener, using the hosted UI sign-in flow, so the authentication challenge is presented before any request is forwarded to the Fargate service. Because the enforcement point is the load balancer rather than the application, the third-party container image needs no changes and no identity provider integration, which is exactly the constraint given.Why the Other Options Are Wrong
B: IAM users with MFA and a resource policy on the Fargate service do not authenticate interactive browser traffic arriving through an ALB, so the service would still be reachable without authentication. C: IAM Identity Center is built for granting access to AWS console and applications, and ALB resource protection does not provide the interactive per-user MFA flow described, so it cannot enforce the allowlist on inbound internet traffic. D: Amazon Amplify does not provide a user pool, and there is no Amplify hosted UI that an ALB listener rule can delegate authentication to, so the option is not a valid service combination.Community Comment Notes
The community voted unanimously 100 to 0 for A, citing the AWS re:Post knowledge center article on authenticating with a Cognito user pool at an Application Load Balancer, and multiple commenters independently identified Cognito as the only service in the list that can front an unmodified application with a user allowlist and MFA.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →