Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 4Objective 3

Authentication and Authorization Defensive Techniques CASENET Practice Questions (Page 4)

Part of the Secure Coding: Authentication and Authorization domain, which makes up ~7% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
7concepts

Questions 16–20

  1. 16application · medium

    A public-facing ASP.NET application has been experiencing brute-force attacks on its login page. The attackers are rotating IP addresses to avoid simple IP-based lockout. The application must slow down automated attacks without affecting legitimate users. Which strategy is most effective?

    Select an answer first
  2. 17expert · hard

    A .NET application has a legacy password hash database using unsalted MD5. The security team wants to upgrade to a secure hashing algorithm without forcing all users to reset their passwords immediately. What is the best migration strategy?

    Select an answer first
  3. 18application · medium

    An ASP.NET application has a login endpoint that is vulnerable to credential stuffing attacks, where attackers use lists of usernames and passwords from other breaches. The application currently has no rate limiting. What is the most effective control to add?

    Select an answer first
  4. 19foundation · easy

    What is the primary security benefit of implementing multi-factor authentication (MFA) in an application?

    Select an answer first
  5. 20application · medium

    A .NET MVC application uses forms authentication with cookies. After a successful login, the user is redirected to a page that displays sensitive data. The security team notices that if a user copies the authentication cookie from one browser to another on a different machine, the session remains valid. The application must prevent this. What should you configure?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.