Courseiva

CCSP Cloud Application Security Practice Question

A cloud-native SaaS provider uses OpenID Connect (OIDC) for user authentication. The security architect wants to reduce the impact of stolen authorization codes and ensure that tokens issued to a single-page application cannot be replayed by a different client. Which OIDC mechanism should be implemented?

⚠ Common exam trap

A common mix-up: candidates confuse token replay mitigations such as DPoP with authorization code protection, when the scenario specifically targets stolen codes and client binding.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use PKCE with the S256 code challenge method and validate the redirect URI against a registered value.

PKCE with S256 ties the authorization code to the initiating client via the code verifier, so a stolen code cannot be redeemed by an attacker who does not possess the verifier. Strict redirect URI validation further constrains where codes and tokens can be delivered. Together they directly mitigate code interception and cross-client replay for public clients like SPAs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the authorization server to use the implicit flow so that no authorization code is ever issued.

    Why it's wrong here

    The implicit flow removes the code but exposes tokens directly in the URL fragment, increasing the risk of token leakage through browser history, referrers, and logs. It is deprecated for SPAs in favor of authorization code with PKCE. Eliminating the code does not solve client binding and introduces worse exposure, so it is the wrong direction.

  • ✗

    Require the authorization server to issue sender-constrained access tokens using Demonstrating Proof of Possession (DPoP).

    Why it's wrong here

    DPoP binds access tokens to a client-held key, which mitigates token replay by other parties. However, the scenario specifically mentions stolen authorization codes and client binding for a single-page application. DPoP addresses access token replay at the resource server, not the code interception or client authentication aspects central to this requirement.

  • ✓

    Use PKCE with the S256 code challenge method and validate the redirect URI against a registered value.

    Why this is correct

    PKCE binds the authorization code to the client that initiated the request by requiring the code verifier at token exchange, preventing a different client from redeeming a stolen code. Combined with strict redirect URI validation, it protects public clients such as SPAs. This directly addresses code interception and client binding, which are the stated concerns.

  • ✗

    Enable refresh token rotation and bind refresh tokens to the client's IP address.

    Why it's wrong here

    Refresh token rotation limits replay of refresh tokens but does not protect authorization codes or bind ID/access tokens to a specific client. IP binding is fragile with mobile and NAT environments and can break legitimate sessions. This does not address the stated goal of preventing a different client from replaying tokens obtained via the authorization code flow.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.