Block fraudulent foreign sign-ups with a pre-sign-up Lambda trigger and a Cognito WAF geo rule

Answer Correct answer: A, B — a pre sign-up Lambda trigger for custom validation plus a WAF geo-match web ACL on the user pool to deny non-France sign-ups.

A company in France uses Amazon Cognito with the Cognito Hosted UI as an identity broker for sign-in and sign-up processes. The company is marketing an application and expects that all the application’s users will come from France. When the company launches the application, the company’s security team observes fraudulent sign-ups for the application. Most of the fraudulent registrations are from users outside of France. The security team needs a solution to perform custom validation at sign-up. Based on the results of the validation, the solution must accept or deny the registration request. Which combination of steps will meet these requirements? (Choose two.)

  1. Create a pre sign-up AWS Lambda trigger. Associate the Amazon Cognito function with the Amazon Cognito user pool. Correct Answer
  2. Use a geographic match rule statement to configure an AWS WAF web ACL Associate the web ACL with the Amazon Cognito user pool. Correct Answer
  3. Configure an app client for the application's Amazon Cognito user pool. Use the app client ID to validate the requests in the hosted UI.
  4. Update the application’s Amazon Cognito user pool to configure a geographic restriction setting.
  5. Use Amazon Cognito to configure a social identity provider (IdP) to validate the requests on the hosted UI.

Community Votes

AB
78%
AD
22%

78% of anonymous learners picked answer AB. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Cognito user pools have no native geographic restriction setting; geo-blocking is done through AWS WAF, which integrates with user pools. The pre sign-up Lambda trigger is the Cognito-native hook for custom validation that can accept or deny a registration based on any logic, including the request's country.

A France-only app sees fraudulent sign-ups from outside France and needs custom accept/deny validation at registration. A pre sign-up AWS Lambda trigger can run arbitrary logic to validate each request and auto-confirm or deny it. Associating an AWS WAF web ACL with a geographic match rule statement to the Cognito user pool blocks requests from disallowed countries at the edge before they reach sign-up.

Expecting a user-pool geographic restriction setting (option D) to exist—it does not; geo control is via WAF. Or relying on an app client ID (option C) for geo validation, which only identifies the client, not the request origin.

Community Discussion (6 comments)

aescudero51 👍 5 Selected: AB
A - is correct. https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-lambda-pre-sign-up.html B - is correct. https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-waf.html#user-pool-waf-setting-up
IPLogic 👍 1 Selected: AB
To meet the requirements, the security team should choose Option A and Option B: A. Create a pre sign-up AWS Lambda trigger. Associate the Amazon Cognito function with the Amazon Cognito user pool. This allows the team to perform custom validation during the sign-up process. The Lambda function can include logic to check the geographic location of the sign-up request and accept or deny it based on whether it originates from France. B. Use a geographic match rule statement to configure an AWS WAF web ACL. Associate the web ACL with the Amazon Cognito user pool. This adds an additional layer of security by using AWS WAF to block sign-up requests from outside France before they reach the Cognito user pool.
navid1365 👍 1 Selected: AB
A and B are correct: -A: AWS documentation explains that you can use pre sign-up Lambda triggers to perform custom validation on user sign-ups. This allows you to accept or deny registration requests based on specific criteria, such as the geographic location of the user. - B: AWS WAF allows you to configure rules that can block requests from specific geographic locations. By associating an AWS WAF web ACL with the Amazon Cognito user pool, you can block sign-up requests from users outside of France.
cumzle_com 👍 1 Selected: AD
Create a pre sign-up AWS Lambda trigger: By associating an Amazon Cognito function with the user pool using a pre sign-up Lambda trigger, you can perform custom validation. This trigger allows you to accept or deny the registration request based on the results of your validation1. Update the application’s Amazon Cognito user pool: Configure a geographic restriction setting within the user pool. This way, you can limit sign-ups to users from specific regions (in this case, France) and prevent fraudulent registrations from outside the expected location1. https://pupuweb.com/aws-certified-security-specialty-qa-combination-steps-perform-custom-validation-sign-up/
sema2232 👍 1
A, C correct
Certified101 👍 1 Selected: AD
The correct answers are A and D. A: Creating a pre sign-up AWS Lambda trigger and associating it with the Amazon Cognito user pool will allow the security team to perform custom validation at sign-up. This Lambda function can be used to check the geographic location of the sign-up request and accept or deny the request based on whether it comes from France. D: Updating the application’s Amazon Cognito user pool to configure a geographic restriction setting will help to ensure that only users from France can sign up for the application. This setting can be used to block sign-up requests that come from outside of France. This is a straightforward way to prevent fraudulent sign-ups from users outside of France. However, it’s important to note that this method might not be 100% effective if the fraudulent users are using VPNs or other methods to appear as though they are in France. Therefore, it’s a good idea to also use the Lambda trigger for additional validation.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A pre sign-up Lambda trigger runs custom validation code on every registration and can return to deny the sign-up, fulfilling the "accept or deny based on validation" requirement. Associating an AWS WAF web ACL with a geographic match rule statement to the user pool blocks requests originating outside France at the edge, directly addressing the fraudulent foreign registrations.

Why the Other Options Are Wrong

C is wrong because an app client ID only identifies the calling application; it cannot validate the geographic origin of a sign-up request. D is wrong because Cognito user pools do not have a built-in geographic restriction setting; geographic control is provided by WAF. E (social IdP) changes the authentication method but performs no custom geo validation or deny logic.

Community Comment Notes

Community favored A,B (78 votes), citing the pre-sign-up Lambda doc and the Cognito WAF setup doc. A minority argued A,D, but commenters clarified that user pools lack a geographic restriction setting and WAF is the mechanism.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide