A company operates a custom online gaming application and uses Amazon Cognito for authentication and authorization. The security engineer needs to implement fine-grained authorization in the application based on existing Cognito user attributes. The company already has a Cognito user pool and identity pool. Which approach meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a policy store in Amazon Verified Permissions. Configure Cognito as the identity source, and map Cognito access tokens to the Verified Permissions schema..
Why this is the answer
Amazon Verified Permissions is designed for fine-grained authorization, allowing you to define granular policies based on user attributes. By configuring Cognito as the identity source and mapping Cognito access tokens to the Verified Permissions schema, you can leverage existing user attributes for authorization decisions within your application. Creating IAM roles and policies with an identity pool provides coarse-grained authorization, granting access to AWS services, not fine-grained application-level authorization based on specific user attributes. AWS Resource Access Manager (RAM) is for sharing AWS resources across accounts or within an organization, not for fine-grained application authorization. Creating IAM users and policies is for managing access to AWS services for individual users or applications, not for integrating with Cognito for fine-grained application authorization.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed