
EC-CouncilCertified Application Security Engineer (.NET)
Domain 6Objective 1
ASP.NET Session Management Techniques CASENET Practice Questions (Page 2)
Part of the Secure Coding: Session Management domain, which makes up ~10% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 6–10
- 6
Which ASP.NET session state mode is best suited for a web farm where session data must survive application pool recycles and be shared across multiple servers?
Select an answer first - 7
A retail company runs an ASP.NET MVC application on two load-balanced web servers. Users frequently lose their shopping cart contents when the load balancer routes a subsequent request to the other server. The IT team wants a solution that maintains session consistency across both servers without requiring changes to the application code. Which session state mode should they configure in web.config?
Select an answer first - 8
An ASP.NET application uses SQLServer session state mode. The development team notices that the application's performance has degraded because large objects are being stored in session state. Which change should they make to improve performance?
Select an answer first - 9
Which configuration setting is a security best practice for session cookies in ASP.NET?
Select an answer first - 10
Which web.config attribute of the <sessionState> element controls whether session IDs are placed in the URL instead of a cookie?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.