Use Amazon Verified Permissions with Cognito as the identity source for fine-grained authorization

Answer Correct answer: B — use Amazon Verified Permissions with Cognito as the identity source, mapping access tokens to the policy schema for fine-grained authorization.

A company runs a custom online gaming application. The company uses Amazon Cognito for user authentication and authorization. A security engineer wants to use AWS to implement fine-grained authorization on resources in the custom application. The security engineer must implement a solution that uses the user attributes that exist in Cognito. The company has already set up a user pool and an identity pool in Cognito. Which solution will meet these requirements?

  1. Create a set of IAM roles and IAM policies. Configure the Cognito identity pool to assign users to the IAM roles.
  2. Create a policy store in Amazon Verified Permissions. Configure Cognito as the identity source. Map Cognito access tokens to the Verified Permissions schema. Correct Answer
  3. Create customer managed permissions by using AWS Resource Access Manager (AWS RAM). Configure the Cognito identity pool to assign users to the customer managed permissions.
  4. Create a set of IAM users and IAM policies. Configure the Cognito user pool to assign users to the IAM users.

Community Votes

B
83%
A
17%

83% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Verified Permissions is purpose-built for fine-grained, attribute-based authorization (ABAC) and integrates natively with Cognito user pools, parsing the JWT claims (user attributes) to make access decisions (B). IAM roles/policies via the identity pool (A) give coarse role-based access, not attribute-level decisions. RAM (C) shares resources, not authorization logic. IAM users per app user (D) does not scale and is not attribute-driven. B is correct.

For fine-grained authorization based on Cognito user attributes, create a policy store in Amazon Verified Permissions, configure Cognito (the existing user/identity pools) as the identity source, and map Cognito access tokens to the Verified Permissions schema. Verified Permissions then evaluates per-request policies against the user's attributes, going beyond role-based IAM for granular, attribute-based access control in the custom app.

Mapping users to IAM roles/policies via the identity pool (A)—that yields role-based access, not the fine-grained, attribute-based decisions the requirement asks for. Using RAM customer-managed permissions (C)—RAM shares resources across accounts, it is not an authorization engine. Creating IAM users per app user (D)—does not scale and ignores Cognito user attributes. Verified Permissions (B) is the ABAC service.

Community Discussion (4 comments)

layrnyh 👍 2 Selected: B
B. Verified Permissions works closely with Amazon Cognito user pools. Amazon Cognito JWTs have a predictable structure. Verified Permissions recognizes this structure and draws maximum benefit from the information that it contains. For example, you can implement a role-based access control (RBAC) authorization model with either ID tokens or access tokens. https://docs.aws.amazon.com/verifiedpermissions/latest/userguide/identity-sources.html
AWSLoverLoverLoverLoverLover 👍 1 Selected: B
The correct answer is B. Amazon Verified Permissions is designed for fine-grained authorization using Cognito user attributes. It allows policies to be defined based on Cognito access tokens and user attributes (e.g., roles, permissions, or group memberships). Mapping Cognito attributes to the Verified Permissions schema ensures dynamic, attribute-based authorization. Why Use Verified Permissions? IAM roles and policies (Option A) control AWS resource access but are not ideal for fine-grained, application-level permissions. Verified Permissions allows policy-based, attribute-driven access control inside a custom application, which is better suited for fine-grained access control in a gaming application.
Pat9595 👍 2 Selected: B
Explanation: Fine-grained authorization requires making access decisions based on user attributes, which go beyond standard IAM role-based access control. Amazon Verified Permissions provides policy-based access control (PBAC), allowing fine-grained authorization by evaluating policies against user attributes from Cognito. Mapping Cognito access tokens to Verified Permissions lets the application dynamically enforce access rules based on user attributes stored in Cognito.
youonebe 👍 1 Selected: A
A is the most straightforward and common solution for implementing fine-grained authorization using user attributes in Amazon Cognito. The approach uses IAM roles and policies, which are well-integrated with Cognito identity pools and can be configured dynamically based on user attributes, enabling fine-grained access control.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Amazon Verified Permissions is a fine-grained, externalized authorization service that supports attribute-based access control. By creating a policy store, configuring Cognito as the identity source, and mapping Cognito access tokens (with their user-attribute claims) to the policy schema, the application can make per-request authorization decisions based on user attributes—exactly the fine-grained requirement, and it reuses the existing Cognito setup.

Why the Other Options Are Wrong

A assigns IAM roles via the identity pool, which provides coarse role-based access rather than attribute-level decisions. C uses RAM, which shares resources across accounts and is not an authorization engine. D creates IAM users per application user, which does not scale and ignores Cognito attributes. B is the purpose-built fine-grained authorization solution.

Community Comment Notes

Community voted B (83), with A a 17 minority. Commenters described Verified Permissions as designed for fine-grained authorization using Cognito user attributes and access tokens, drawing maximum benefit from the JWT claim structure; A was seen as the simpler but coarser role-based alternative. B confirmed.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide