nerdexam
Amazon

SAP-C02 · Question #231

A solutions architect wants to make sure that only AWS users or roles with suitable permissions can access a new Amazon API Gateway endpoint. The solutions architect wants an end-to-end view of each…

The correct answer is A. For the API Gateway method, set the authorization to AWSJAM. https://aws.amazon.com/premiumsupport/knowledge-center/iam-authentication-api-gateway/

Submitted by brentm· Mar 6, 2026Design for New Solutions

Question

A solutions architect wants to make sure that only AWS users or roles with suitable permissions can access a new Amazon API Gateway endpoint. The solutions architect wants an end-to-end view of each request to analyze the latency of the request and create service maps. How can the solutions architect design the API Gateway access control and perform request inspections?

Options

  • AFor the API Gateway method, set the authorization to AWSJAM.
  • BFor the API Gateway resource set CORS to enabled and only return the company's domain in
  • CCreate an AWS Lambda function as the custom authorizer ask the API client to pass the key and
  • DCreate a client certificate for API Gateway.

How the community answered

(45 responses)
  • A
    73% (33)
  • B
    9% (4)
  • C
    13% (6)
  • D
    4% (2)

Explanation

https://aws.amazon.com/premiumsupport/knowledge-center/iam-authentication-api-gateway/

Community Discussion

No community discussion yet for this question.

Full SAP-C02 Practice