Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 4Objective 3

Authentication and Authorization Defensive Techniques CASENET Practice Questions (Page 3)

Part of the Secure Coding: Authentication and Authorization domain, which makes up ~7% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
7concepts

Questions 11–15

  1. 11foundation · easy

    In an ASP.NET Core application, which authentication mechanism is most appropriate when the application needs to authenticate users against an existing Active Directory domain and automatically use the logged-in Windows user's identity?

    Select an answer first
  2. 12expert · hard

    A .NET application currently uses forms authentication with cookies. The security team wants to move to token-based authentication to support a mobile app. The application must also maintain session security. Which approach should be taken?

    Select an answer first
  3. 13expert · hard

    A .NET application uses claims-based authorization. A user's claims are issued at login and stored in the authentication cookie. The business now requires that some permissions be revocable immediately when a user's employment status changes. Which approach should be used?

    Select an answer first
  4. 14expert · hard

    A .NET application has implemented TOTP-based MFA. Users are reporting that they are being locked out of their accounts because their authenticator app and the server are out of sync (time drift). The application uses a strict time window of 30 seconds. What is the best way to handle this without compromising security?

    Select an answer first
  5. 15foundation · easy

    Which authorization strategy in ASP.NET Core is most appropriate when you need to restrict access to an action method to users who belong to the 'Administrator' role?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.