Put Amazon Cognito authentication with MFA in front of a Fargate application on an ALB

Answer Correct answer: A — Create a Cognito user pool requiring MFA and configure an ALB listener rule to authenticate through the hosted UI.

A company is deploying a third-party web application on AWS. The application is packaged as a Docker image. The company has deployed the Docker image as an AWS Fargate service in Amazon Elastic Container Service (Amazon ECS). An Application Load Balancer (ALB) directs traffic to the application. The company needs to give only a specific list of users the ability to access the application from the internet. The company cannot change the application and cannot integrate the application with an identity provider. All users must be authenticated through multi-factor authentication (MFA). Which solution will meet these requirements?

  1. Create a user pool in Amazon Cognito. Configure the pool for the application. Populate the pool with the required users. Configure the pool to require MFConfigure a listener rule on the ALB to require authentication through the Amazon Cognito hosted UI. Correct Answer
  2. Configure the users in AWS Identity and Access Management (IAM). Attach a resource policy to the Fargate service to require users to use MFA. Configure a listener rule on the ALB to require authentication through IAM.
  3. Configure the users in AWS Identity and Access Management (IAM). Enable AWS IAM Identity Center (AWS Single Sign-On). Configure resource protection for the ALB. Create a resource protection rule to require users to use MFA.
  4. Create a user pool in AWS Amplify. Configure the pool for the application. Populate the pool with the required users. Configure the pool to require MFA. Configure a listener rule on the ALB to require authentication through the Amplify hosted UI.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

ALB supports native authentication with a Cognito user pool, so the identity check happens at the listener before traffic ever reaches the Fargate tasks, which is what allows an unmodified third-party application to sit behind an authenticated endpoint.

A third-party Docker image runs as a Fargate service behind an Application Load Balancer, and only a specific list of users may reach it from the internet. The application cannot be changed and cannot be integrated with an identity provider, and every user must authenticate with multi-factor authentication.

Attaching a resource policy to the Fargate service to require MFA. Resource policies on a compute service do not enforce end-user authentication, and IAM identities are for AWS principals such as roles and users signing API calls, not for interactive browser sessions arriving through a load balancer.

Community Discussion (10 comments)

JMAN1 👍 9 Selected: A
A? As GPT says, In this scenario, setting up a user pool in Amazon Cognito allows you to define the specific list of users who can access the application. You can configure the user pool to require multi-factor authentication (MFA), ensuring an additional layer of security for user authentication. Configuring the ALB listener rule to require authentication through the Amazon Cognito hosted UI means that users attempting to access the application through the ALB will be redirected to the Cognito hosted UI for authentication, where they'll need to provide their credentials and MFA code. This setup ensures that only authenticated users from the specific user pool with MFA will have access to the application, meeting the requirements without modifying the application itself.
thotwielder 👍 6
web application = Cognito
career360guru 👍 4 Selected: A
As application can not be changed to integrate with Identity provider and users needs to be authenticated from internet using Cognito is the only possible solution among the options.
duriselvan 👍 3
A ans https://repost.aws/knowledge-center/cognito-user-pool-alb-authentication
igor12ghsj577 👍 1
A sounds OK
tmlong18 👍 1 Selected: A
Answer is A ALB authentication only integration with: Cognito AWS_IAM Lambda authorizer
career360guru 👍 1 Selected: A
Answer is A
Laercio96 👍 1
Answer is A
clevvve 👍 1
B&C is for accessing aws resources
clevvve 👍 1 Selected: A
Answer is A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

An Amazon Cognito user pool holds the specific list of permitted users and can be configured to require MFA, which satisfies both the user allowlist and the multi-factor requirement. The Application Load Balancer can be configured to authenticate users against a Cognito user pool on its listener, using the hosted UI sign-in flow, so the authentication challenge is presented before any request is forwarded to the Fargate service. Because the enforcement point is the load balancer rather than the application, the third-party container image needs no changes and no identity provider integration, which is exactly the constraint given.

Why the Other Options Are Wrong

B: IAM users with MFA and a resource policy on the Fargate service do not authenticate interactive browser traffic arriving through an ALB, so the service would still be reachable without authentication. C: IAM Identity Center is built for granting access to AWS console and applications, and ALB resource protection does not provide the interactive per-user MFA flow described, so it cannot enforce the allowlist on inbound internet traffic. D: Amazon Amplify does not provide a user pool, and there is no Amplify hosted UI that an ALB listener rule can delegate authentication to, so the option is not a valid service combination.

Community Comment Notes

The community voted unanimously 100 to 0 for A, citing the AWS re:Post knowledge center article on authenticating with a Cognito user pool at an Application Load Balancer, and multiple commenters independently identified Cognito as the only service in the list that can front an unmodified application with a user allowlist and MFA.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide