Question 1 · choose 1
A mobile app signs users in with an Amazon Cognito user pool. Signed-in users must upload photos from the app directly to an Amazon S3 bucket, and each user may write only under a prefix named after that user's identity. The app must not contain long-term AWS credentials. What should the developer use?
- AA Cognito identity pool that exchanges the token for temporary role credentials
- BAn IAM user for each app user, with that user's access keys stored in the app
- CA bucket policy that allows anyone to call PutObject under an uploads/ prefix
- DA Lambda authorizer that checks the user pool token before each upload to S3
Show the answer and why
AA Cognito identity pool that exchanges the token for temporary role credentials
Correct
An identity pool exchanges a user pool token for temporary AWS credentials. The role's policy can use the cognito-identity.amazonaws.com:sub variable to limit each user to their own prefix.
BAn IAM user for each app user, with that user's access keys stored in the app
Incorrect
Access keys are long-term credentials. IAM best practices call for temporary credentials through federation and roles instead.
CA bucket policy that allows anyone to call PutObject under an uploads/ prefix
Incorrect
This makes the bucket writable by the public, which S3 Block Public Access exists to prevent, and it cannot limit a user to their own prefix.
DA Lambda authorizer that checks the user pool token before each upload to S3
Incorrect
Lambda authorizers control access to API Gateway methods. They play no part in requests that the app sends straight to Amazon S3.
User pools authenticate users; identity pools turn that authentication into scoped, temporary AWS credentials for direct calls to AWS services.
AWS documentation