
EC-CouncilCertified Application Security Engineer (.NET)
Domain 2Objective 2
Abuse Case and Security Use Case Modeling CASENET Practice Questions (Page 1)
Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
7concepts
Questions 1–5
- 1
During a design review, a developer says, 'We already have a use case for user login, so we don't need an abuse case for it.' Which response best clarifies the difference?
Select an answer first - 2
During a threat modeling workshop, the team identified an abuse case where an attacker could intercept and modify a customer's order details during transmission. The team needs to document a functional requirement that directly mitigates this threat. Which of the following best represents a security use case?
Select an answer first - 3
A security analyst is creating abuse cases for a new online payment system. The team has a use case diagram. Which sequence of steps best follows the abuse case creation process?
Select an answer first - 4
When deriving a security use case from an abuse case, what should be specified?
Select an answer first - 5
A team is modeling threats for an e-commerce application. They want to visualize how an attacker could misuse the 'Place Order' use case. Which UML-style diagram is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.