Block fraudulent foreign sign-ups with a pre-sign-up Lambda trigger and a Cognito WAF geo rule
A company in France uses Amazon Cognito with the Cognito Hosted UI as an identity broker for sign-in and sign-up processes. The company is marketing an application and expects that all the application’s users will come from France. When the company launches the application, the company’s security team observes fraudulent sign-ups for the application. Most of the fraudulent registrations are from users outside of France. The security team needs a solution to perform custom validation at sign-up. Based on the results of the validation, the solution must accept or deny the registration request. Which combination of steps will meet these requirements? (Choose two.)
Community Votes
78% of anonymous learners picked answer AB. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Cognito user pools have no native geographic restriction setting; geo-blocking is done through AWS WAF, which integrates with user pools. The pre sign-up Lambda trigger is the Cognito-native hook for custom validation that can accept or deny a registration based on any logic, including the request's country.
A France-only app sees fraudulent sign-ups from outside France and needs custom accept/deny validation at registration. A pre sign-up AWS Lambda trigger can run arbitrary logic to validate each request and auto-confirm or deny it. Associating an AWS WAF web ACL with a geographic match rule statement to the Cognito user pool blocks requests from disallowed countries at the edge before they reach sign-up.
Expecting a user-pool geographic restriction setting (option D) to exist—it does not; geo control is via WAF. Or relying on an app client ID (option C) for geo validation, which only identifies the client, not the request origin.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.