
EC-CouncilCertified Application Security Engineer (.NET)
Domain 6Objective 1
ASP.NET Session Management Techniques CASENET Practice Questions (Page 5)
Part of the Secure Coding: Session Management domain, which makes up ~10% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 21–25
- 21
Which of the following is a recommended measure to prevent session hijacking in an ASP.NET application?
Select an answer first - 22
Which event in the Global.asax file is raised when a session is abandoned or expires?
Select an answer first - 23
A security audit reveals that the session cookie is not marked as Secure. The application is served over HTTPS. What is the risk of not setting the Secure flag?
Select an answer first - 24
Which practice is recommended to optimize ASP.NET session state performance?
Select an answer first - 25
What is a key requirement for using StateServer session state mode in a web farm?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.