passdrill
AWS SAA-C03 · IAM & Security · Card 023/024 easy

A mobile app lets users browse public content without signing in, but if a user signs in through a supported social identity provider, the app should let that user upload files directly to an S3 bucket using temporary AWS credentials scoped to their identity, without the app's backend ever handling long-lived AWS credentials. Which service is designed for this?

  1. IAM Identity Center, which provides workforce single sign-on to multiple AWS accounts and business applications
  2. AWS STS AssumeRole called directly from the mobile app using a long-lived IAM user access key embedded in the app
  3. Amazon Cognito identity pools, which issue temporary AWS credentials scoped to an IAM role for both unauthenticated guest users and users authenticated through a supported identity provider
  4. AWS Directory Service, which provides a managed Microsoft Active Directory for domain-joined workloads
Next card → Shuffle