Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A company has a web application running on EC2 instances behind an Application Load Balancer (ALB). The application uses sticky sessions (session affinity) based on cookies. Recently, the SysOps team noticed that user sessions are being lost intermittently, causing users to be logged out. The team checks the ALB configuration and finds that the stickiness is enabled with a cookie name 'AWSALB' and duration of 1 hour. The application also sets its own cookie. What is the most likely cause of session loss?

⚠ Common exam trap

SOA-C02 often tests the confusion between ALB stickiness and application session management, leading candidates to blame the ALB cookie or health checks instead of misaligned timeouts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The application's session cookie has a shorter expiration than the ALB's stickiness duration

The most likely cause is that the application's session cookie expires before the ALB's stickiness cookie, causing the user to be logged out even though the ALB still routes to the same instance. The ALB stickiness duration is 1 hour, but if the application cookie has a shorter lifespan, the session ends prematurely. This is a common misconfiguration when application and load balancer session timeouts are not aligned.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The ALB's health check interval is too short, causing instances to be marked unhealthy

    Why it's wrong here

    The ALB health check interval determines how frequently the load balancer sends requests to an instance to assess its status, but it has no effect on the persistence of client sessions. A shorter interval merely increases probe frequency; as long as the instance continues to return healthy responses, it remains eligible to receive traffic and its existing stickiness cookies remain valid. Session loss here is caused by the application-side session expiring before the ALB's stickiness duration, not by any health check misconfiguration.

  • ✗

    The application cookie is overwriting the ALB's stickiness cookie

    Why it's wrong here

    The ALB's stickiness feature uses a dedicated, load-balancer-generated cookie (typically named AWSALB) that is encrypted and stored separately from any application cookies. An application cookie, such as a session identifier, cannot overwrite or corrupt the ALB's stickiness cookie because they use different names and are written by different layers. Even if an application attempts to set a cookie with the same name, the ALB overwrites it with its own value on the response, ensuring that the routing persistence remains intact. Therefore, cookie interference is not a plausible cause of lost sessions.

  • ✗

    Cross-zone load balancing is disabled on the ALB

    Why it's wrong here

    Cross-zone load balancing controls whether an ALB node can distribute traffic to targets located in other Availability Zones; when disabled, each node only receives traffic from its own zone and routes to targets in that same zone. This setting affects the distribution of load across AZs but does not alter how the ALB uses its stickiness cookie to route a client to the same target instance. A client's session will still be pinned to the same instance as long as the cookie is valid, regardless of the cross-zone setting. Thus, this misconfiguration cannot explain why sessions are lost.

  • ✓

    The application's session cookie has a shorter expiration than the ALB's stickiness duration

    Why this is correct

    In this scenario, the ALB's stickiness cookie (AWSALB) remains valid and continues to route the client to the same EC2 instance for the configured duration, but the application's own session cookie (e.g., JSESSIONID) expires earlier. Once the application session expires, the server-side session data is discarded or considered invalid, causing the user to be logged out even though the ALB still sends them to the exact same server. The user then perceives a lost session, but the underlying issue is the mismatch between the application session timeout and the ALB stickiness duration, not the load balancer's routing behavior.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.