Answer: B
A mobile app that becomes popular can have a large user base. The best way to provide access to AWS resources in this scenario will be to use Federated Identity access using External Identity Providers(IdP) like Amazon, Facebook, Google etc. The mobile app can establish trust with these well-known IdPs and take advantage of the authentication mechanisms to validate user identity. As shown in the figure below, the mobile app uses Amazon as the external IdP for accepting user credentials & authenticating him. Using Cognito & the Security Token Service, the Mobile App then gets temporary Security Credentials for accessing the AWS resources required by the app. The role associated with the STS token and its assigned policies determine what can be accessed.
Option A is incorrect. Distributing long-term AWS Security Credentials with external applications is not recommended since the credentials may be compromised resulting in security breaches.
Option B is CORRECT. The STS token will contain temporary credentials with a Role indicating the access level that a mobile app user can have. The security credentials will be valid for a specific user session only.
Option C is incorrect. Creating an ever-growing set of Users within AWS IAM and assigning them permissions for accessing AWS resources will be impractical.
Option D is incorrect. Although it is a viable option to connect to an EC2 instance running a similar web application, it will duplicate effort on the developer’s part.
References:
https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_oidc_cognito.html
https://www.testpreptraining.com/tutorial/aws-cloud-practitioner/aws-access-management/
https://docs.aws.amazon.com/IAM/latest/UserGuide/introduction.html