QuestionQ16

Identity and Access Management

A company in France uses Amazon Cognito with the Cognito Hosted UI as an identity broker for its sign-in and sign-up processes. The company is marketing an application and expects that every application user will be from France.

When the company launches the application, its security team notices fraudulent application sign-ups. Most fraudulent registrations originate from users outside France.

The security team requires a solution that performs custom validation at sign-up. Based on the validation results, the solution must allow or deny the registration request.

Which combination of steps meets these requirements?

Choose two
Explanation

An Amazon Cognito pre sign-up Lambda trigger performs custom validation and can accept or deny a sign-up request. An AWS WAF web ACL associated with the Cognito user pool protects Hosted UI requests; a geographic match rule can use the request’s country of origin to block registrations from outside France.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!