
EC-CouncilCertified Application Security Engineer (.NET)
Domain 5Objective 2
Asymmetric Encryption and Defensive Coding CASENET Practice Questions (Page 2)
Part of the Secure Coding: Cryptography domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
7concepts
Questions 6–10
- 6
A developer is designing a secure communication protocol for a mobile app. The app needs to encrypt messages and ensure forward secrecy. Which approach should the developer use?
Select an answer first - 7
A security audit of a .NET application found that it uses RSA with a 1024-bit key. The application is used for both encryption and signing. What is the most appropriate action?
Select an answer first - 8
What is a primary difference between symmetric and asymmetric encryption?
Select an answer first - 9
A developer is implementing digital signatures in .NET and wants to use ECDSA. What is a key advantage of ECDSA over RSA for digital signatures?
Select an answer first - 10
A .NET developer is implementing RSA decryption in a web service. The service returns different error messages for invalid padding and invalid ciphertext. What vulnerability does this introduce?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.