AnswerCorrect answer: C — migrate authentication to Amazon Cognito user pools federated with third-party IdPs to offload password resets.
A company runs an online game on AWS. When players sign up for the game, their username and password credentials are stored in an Amazon Aurora database. The number of users has grown to hundreds of thousands of players. The number of requests for password resets and login assistance has become a burden for the company's customer service team. The company needs to implement a solution to give players another way to log in to the game. The solution must remove the burden of password resets and login assistance while securely protecting each player's credentials. Which solution will meet these requirements?
When a new player signs up, use an AWS Lambda function to automatically create an IAM access key and a secret access key. Program the Lambda function to store the credentials on the player's device. Create IAM keys for existing players.
Migrate the player credentials from the Aurora database to AWS Secrets Manager. When a new player signs up, create a key-value pair in Secrets Manager for the player’s user ID and password.
Configure Amazon Cognito user pools to federate access to the game with third-party identity providers (IdPs), such as social IdPs. Migrate the game’s authentication mechanism to Cognito. Correct Answer
Instead of using usernames and passwords for authentication, issue API keys to new and existing players. Create an Amazon API Gateway API to give the game client access to the game’s functionality.
Community Votes
C
100%
100% of anonymous learners picked answer C.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Cognito user pools provide scalable, secure authentication with built-in self-service password recovery, MFA, and IdP federation, directly removing the support burden. Storing player credentials in Secrets Manager (B) or handing out IAM access keys/API keys (A/D) is insecure anti-pattern—exposing AWS credentials to end users or reimplementing auth poorly. C is the only fit.
An online game with hundreds of thousands of users is overwhelmed by password-reset and login-assistance requests. Moving authentication to Amazon Cognito user pools (and federating with social/third-party IdPs) offloads credential management, self-service password reset, and MFA to a managed service, removing the burden from customer support while securely protecting each player's credentials.
Issuing IAM access keys (A) or API keys (D) to players—this exposes AWS credentials/secrets to end users, a serious security anti-pattern. Moving credentials to Secrets Manager (B) still leaves the company building and operating its own auth and reset flow. Cognito (C) is the managed auth service designed for this.
Community Discussion (3 comments)
phmeeeee👍 1Selected: C
C - By leverage Amazon Connito to do that.
HunkyBunky👍 1Selected: C
I'm agreed - that only C looks good in this scenario
aescudero51👍 4Selected: C
Answer is C This solution addresses the burden of password resets and login assistance by leveraging Amazon Cognito, which provides a scalable and secure authentication mechanism. By federating access to the game with third-party identity providers, players can log in using their existing social media credentials, eliminating the need for password resets and login assistance. This approach also ensures that each player's credentials are securely protected, as Cognito handles the authentication and authorization processes
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
Amazon Cognito user pools are a managed identity store that handle registration, authentication, self-service password reset, MFA, and federation with social/third-party IdPs. Migrating the game's auth to Cognito offloads the password-reset and login-assistance burden from customer support while securely managing each player's credentials at scale.
Why the Other Options Are Wrong
A issues IAM access/secret keys to players and stores them on devices—an unsafe anti-pattern that exposes AWS credentials to end users. B moves credentials to Secrets Manager but still requires the company to build and run its own auth/reset flow. D replaces passwords with API keys, again exposing long-lived secrets to clients. C is the managed, secure choice.
Community Comment Notes
Community voted C (100). Commenters agreed only C is sensible, leveraging Cognito to offload authentication and password resets via federation. A, B, and D were dismissed as insecure or as still burdening the team.