
EC-CouncilCertified Application Security Engineer (.NET)
Domain 2Objective 2
Abuse Case and Security Use Case Modeling CASENET Practice Questions (Page 5)
Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
7concepts
Questions 21–25
- 21
A team has defined an abuse case where an attacker can access sensitive data by exploiting a broken access control in a REST API. They have defined a security use case that requires role-based access control (RBAC) checks on every API endpoint. The team is now integrating this into the system design. Which integration step is most critical to ensure the security use case is effective?
Select an answer first - 22
A team is starting abuse case modeling for a new document management system. They have identified the primary use case 'User uploads a document.' Which sequence of steps best follows the abuse case creation process?
Select an answer first - 23
A security analyst has documented an abuse case where an attacker bypasses authentication by replaying a captured session token. The team needs to define a security use case to mitigate this. What should the security use case specify?
Select an answer first - 24
A team has identified an abuse case where an attacker can upload a malicious file to a document management system. They have defined a security use case to validate file types and scan for malware. What is the next step to ensure the security requirement is addressed?
Select an answer first - 25
What is the first step in creating abuse cases from use cases?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.