Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 6Objective 1

ASP.NET Session Management Techniques CASENET Practice Questions (Page 8)

Part of the Secure Coding: Session Management domain, which makes up ~10% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
8concepts

Questions 36–38

  1. 36application · medium

    An ASP.NET application must support clients that have cookies disabled. The developer sets cookieless="UseUri" in web.config. What additional configuration is essential to prevent session ID leakage through HTTP referrer headers?

    Select an answer first
  2. 37application · medium

    A healthcare application stores sensitive patient data in session state. The security team requires that session data be protected even if the server's memory is compromised. Which configuration should be used?

    Select an answer first
  3. 38application · medium

    An e-commerce application currently uses InProc session state. The operations team wants to move to SQLServer mode to support a web farm. They have created a database and run the necessary scripts. Which web.config configuration is required to enable SQLServer session state?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CASENET

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.