
EC-CouncilCertified Application Security Engineer (.NET)
Domain 5Objective 2
Asymmetric Encryption and Defensive Coding CASENET Practice Questions (Page 6)
Part of the Secure Coding: Cryptography domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
7concepts
Questions 26–28
- 26
A .NET developer is implementing RSA encryption for a legacy system that only supports PKCS#1 v1.5 padding. The system is exposed to the internet and handles sensitive data. Which mitigation is most effective to reduce the risk of padding oracle attacks?
Select an answer first - 27
A developer is implementing RSA encryption in a .NET application and needs to choose a padding scheme. The application will encrypt small session keys that are sent to a server. Which padding scheme should the developer use to prevent padding-oracle attacks?
Select an answer first - 28
A .NET developer is designing a system that encrypts large files for multiple recipients. Each recipient should be able to decrypt the file independently. Which approach is most efficient and secure?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CASENET
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.