Enforce OIDC authentication on the ALB so only authenticated users reach the backends
A company needs to improve the security of its web-based application on AWS. The application uses Amazon CloudFront with two custom origins. The first custom origin routes requests to an Amazon API Gateway HTTP API. The second custom origin routes traffic to an Application Load Balancer (ALB). The application integrates with an OpenID Connect (OIDC) identity provider (IdP) for user management. A security audit shows that a JSON Web Token (JWT) authorizer provides access to the API. The security audit also shows that the ALB accepts requests from unauthenticated users. A solutions architect must design a solution to ensure that all backend services respond to only authenticated users. Which solution will meet this requirement?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
An Application Load Balancer can natively authenticate requests against an OIDC identity provider, so the missing control is added at the load balancer rather than in the application, and it protects the ALB origin and anything behind it without changing the application.
CloudFront fronts two custom origins, an API Gateway HTTP API protected by a JWT authorizer and an Application Load Balancer that a security audit found accepts unauthenticated requests. The application integrates with an OpenID Connect identity provider, and every backend service must respond only to authenticated users.
Adding a WAF web ACL to filter unauthenticated requests. A web ACL matches on IP addresses, geographic location, request properties, and managed rule lists such as SQL injection, and it has no awareness of whether a request carries a valid identity token, so it cannot make that determination.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
An Application Load Balancer supports authenticate actions that validate users against an OpenID Connect identity provider before any request is forwarded to the registered targets. Because the identity provider is already integrated with the application, configuring the ALB to use it means the sign-in happens at the load balancer and only authenticated users reach the backend. This closes the exact gap the audit found, and because enforcement is at the listener it applies to everything behind the ALB without any application change, and CloudFront continues to serve the same origins.Why the Other Options Are Wrong
B: A permissive signed URL policy allows any request to access the content, which is the opposite of restricting access, and CloudFront signed URLs do not authenticate users against the OIDC provider for the ALB origin anyway. C: A WAF web ACL has no visibility into whether a request is authenticated, so it cannot filter unauthenticated requests; it can restrict by IP or match known exploit patterns but not by identity. D: Enabling CloudTrail and analysing the logs in Lambda is a detective control that runs after the request has already been served, so it can report unauthorised access but cannot prevent it, and it would add latency rather than improve response behaviour.Community Comment Notes
The community voted 100 to 0 for A, and the top-voted comment linked the AWS documentation on authenticating users through an Application Load Balancer, which describes exactly the OIDC integration the question describes.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →