Subdomain 1.2: Design secure workloads and applications
1.A company is building a mobile application that must let customers sign up and sign in with an email address and password, and after authentication the app must obtain temporary AWS credentials so it can upload photos directly to an Amazon S3 bucket. Which combination of Amazon Cognito components should the solutions architect use?
- A.Use a Cognito user pool to handle customer sign-up and sign-in, then configure a Cognito identity pool that accepts the user pool's tokens and exchanges them for temporary IAM credentials scoped to the S3 upload permissions.
- B.Use a Cognito identity pool to handle customer sign-up and sign-in directly, then configure a Cognito user pool to exchange the identity pool's session tokens for temporary IAM credentials scoped to S3.
- C.Use a single Cognito user pool for both authentication and AWS credential exchange, since user pools issue IAM-scoped temporary credentials directly to authenticated app users without needing a separate identity pool at all.
- D.Use AWS IAM Identity Center to authenticate the mobile application's customers against a corporate directory, then assign each customer a permission set that grants direct access to the S3 bucket.
Show answer & explanation
Correct answer: A — Use a Cognito user pool to handle customer sign-up and sign-in, then configure a Cognito identity pool that accepts the user pool's tokens and exchanges them for temporary IAM credentials scoped to the S3 upload permissions.
- A. A user pool is a user directory that handles sign-up, sign-in, and issues authentication tokens after a successful login. An identity pool takes those tokens as a trusted identity provider and exchanges them for temporary IAM credentials, which is exactly the pairing needed to authenticate customers and then let the app call S3 directly.
- B. This reverses the roles of the two components: identity pools do not provide sign-up or sign-in functionality, and user pools do not exchange session tokens for AWS credentials. Sign-up and sign-in belong to the user pool, and credential exchange belongs to the identity pool.
- C. A user pool issues JSON web tokens after authentication, but it does not issue temporary AWS IAM credentials on its own; that exchange is the specific job of an identity pool, which is required to grant the app access to call S3.
- D. IAM Identity Center is designed for workforce access to AWS accounts and business applications through a corporate or external directory, not for authenticating a public mobile application's customers, so it is not the appropriate service for this consumer-facing sign-up flow.