Courseiva
Cloud Application Security →mediumMultiple Choice

CCSP Cloud Application Security Practice Question

A large enterprise is migrating a legacy .NET application to Azure App Service. The application currently stores session state in-memory on the web server. During the migration, the team plans to horizontally scale the application across multiple instances. The security team requires that session data remain confidential and be available even if an instance fails. Which solution should the team implement?

⚠ Common exam trap

ISC2 often tests the distinction between availability and affinity, where candidates mistakenly choose sticky sessions (Option D) thinking they solve availability, but sticky sessions actually create a single point of failure by binding a user to one instance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Azure Redis Cache to store session state with encryption enabled

Azure Redis Cache with encryption enabled provides a secure, centralized session store that persists data independently of individual web server instances. This ensures session data remains available even if an instance fails, and encryption protects confidentiality in transit and at rest, meeting the security team's requirements for horizontal scaling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store session data in Azure SQL Database with column-level encryption

    Why it's wrong here

    Azure SQL Database does not provide the shared, low-latency session store that App Service instances require, and column-level encryption protects stored columns rather than the session payload itself. It would suit durable relational records needing field-level protection, not cross-instance session state.

  • ✓

    Use Azure Redis Cache to store session state with encryption enabled

    Why this is correct

    Azure Redis Cache externalises session state from instance memory, so any scaled instance can read the same data and a failed instance loses nothing. Encryption at rest and in transit keeps the session data confidential, meeting both availability and confidentiality constraints.

  • ✗

    Encrypt session data and store it as a client-side cookie

    Why it's wrong here

    Client-side cookies place session data on the user's device, so confidentiality depends on encryption keys the client can reach, and the data is lost if the cookie is dropped. Cookies suit stateless preferences or tokens, not server-side session state that must survive an instance failure.

  • ✗

    Configure Application Gateway with cookie-based affinity (sticky sessions)

    Why it's wrong here

    Cookie-based affinity pins each user to one instance, so session data still resides in that instance's memory and is lost when it fails. Affinity suits legacy applications that cannot externalise state, not the stated requirement for availability across instance failure.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.