Enforce OIDC authentication on the ALB so only authenticated users reach the backends

Answer Correct answer: A — Configure the ALB to authenticate and authorize against the OIDC identity provider so only authenticated users reach the backends.

A company needs to improve the security of its web-based application on AWS. The application uses Amazon CloudFront with two custom origins. The first custom origin routes requests to an Amazon API Gateway HTTP API. The second custom origin routes traffic to an Application Load Balancer (ALB). The application integrates with an OpenID Connect (OIDC) identity provider (IdP) for user management. A security audit shows that a JSON Web Token (JWT) authorizer provides access to the API. The security audit also shows that the ALB accepts requests from unauthenticated users. A solutions architect must design a solution to ensure that all backend services respond to only authenticated users. Which solution will meet this requirement?

  1. Configure the ALB to enforce authentication and authorization by integrating the ALB with the IdP. Allow only authenticated users to access the backend services. Correct Answer
  2. Modify the CloudFront configuration to use signed URLs. Implement a permissive signing policy that allows any request to access the backend services.
  3. Create an AWS WAF web ACL that filters out unauthenticated requests at the ALB level. Allow only authenticated traffic to reach the backend services.
  4. Enable AWS CloudTrail to log all requests that come to the ALB. Create an AWS Lambda function to analyze the logs and block any requests that come from unauthenticated users.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

An Application Load Balancer can natively authenticate requests against an OIDC identity provider, so the missing control is added at the load balancer rather than in the application, and it protects the ALB origin and anything behind it without changing the application.

CloudFront fronts two custom origins, an API Gateway HTTP API protected by a JWT authorizer and an Application Load Balancer that a security audit found accepts unauthenticated requests. The application integrates with an OpenID Connect identity provider, and every backend service must respond only to authenticated users.

Adding a WAF web ACL to filter unauthenticated requests. A web ACL matches on IP addresses, geographic location, request properties, and managed rule lists such as SQL injection, and it has no awareness of whether a request carries a valid identity token, so it cannot make that determination.

Community Discussion (6 comments)

kejam 👍 10 Selected: A
https://docs.aws.amazon.com/elasticloadbalancing/latest/application/listener-authenticate-users.html
AzureDP900 👍 1
Option A is right, this solution meets the requirement of ensuring that all backend services respond to only authenticated users: 1) Authentication at the load balancer level: By configuring the ALB to integrate with the OIDC IdP, you can enforce authentication and authorization for incoming requests. 2) Preventing unauthenticated requests: The ALB will reject any requests from unauthenticated users, ensuring that only authenticated users can access the backend services.
career360guru 👍 1 Selected: A
Option A
a54b16f 👍 2 Selected: A
A is right
TheCloudGuruu 👍 2 Selected: A
Answer is A
alexis123456 👍 3
correct Answer is A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

An Application Load Balancer supports authenticate actions that validate users against an OpenID Connect identity provider before any request is forwarded to the registered targets. Because the identity provider is already integrated with the application, configuring the ALB to use it means the sign-in happens at the load balancer and only authenticated users reach the backend. This closes the exact gap the audit found, and because enforcement is at the listener it applies to everything behind the ALB without any application change, and CloudFront continues to serve the same origins.

Why the Other Options Are Wrong

B: A permissive signed URL policy allows any request to access the content, which is the opposite of restricting access, and CloudFront signed URLs do not authenticate users against the OIDC provider for the ALB origin anyway. C: A WAF web ACL has no visibility into whether a request is authenticated, so it cannot filter unauthenticated requests; it can restrict by IP or match known exploit patterns but not by identity. D: Enabling CloudTrail and analysing the logs in Lambda is a detective control that runs after the request has already been served, so it can report unauthorised access but cannot prevent it, and it would add latency rather than improve response behaviour.

Community Comment Notes

The community voted 100 to 0 for A, and the top-voted comment linked the AWS documentation on authenticating users through an Application Load Balancer, which describes exactly the OIDC integration the question describes.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide