A developer is looking at establishing access control for an API that connects to a Lambda function downstream. Which of the following represents a mechanism that CANNOT be used for authenticating with the API Gateway? A. API Key B. AWS Identity and Access Management (IAM) C. OAuth 2.0 D. X.509 client certificates