
EC-CouncilCertified Application Security Engineer (.NET)
Domain 4Objective 3
Authentication and Authorization Defensive Techniques CASENET Practice Questions (Page 6)
Part of the Secure Coding: Authentication and Authorization domain, which makes up ~7% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
7concepts
Questions 26–30
- 26
Which of the following is a recommended password hashing algorithm for securely storing passwords in a .NET application?
Select an answer first - 27
A .NET application has a session timeout of 60 minutes. A security audit recommends reducing the risk of session hijacking. Which change should be made to the session configuration?
Select an answer first - 28
A .NET application is being updated to support MFA. The current login flow only asks for username and password. The security team wants to require MFA for all users, but the help desk is concerned about users losing their phones. Which MFA strategy balances security and usability?
Select an answer first - 29
Which technique is commonly used to limit the rate of requests to an authentication endpoint to mitigate brute-force attacks?
Select an answer first - 30
A .NET application stores user passwords in a database. The current implementation uses SHA-256 without salt. The security team has mandated a more secure password storage scheme. Which approach should you implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.