
EC-CouncilCertified Application Security Engineer (.NET)
Domain 4Objective 1
Common Threats on User Authentication and Authorization CASENET Practice Questions (Page 2)
Part of the Secure Coding: Authentication and Authorization domain, which makes up ~7% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
Questions 6–10
- 6
A large enterprise application uses a centralized identity provider (IdP) and issues JWTs to clients. The IdP has a bug that occasionally issues tokens with the 'Admin' role to non-admin users. The application team cannot immediately fix the IdP bug. They need to mitigate the risk of privilege escalation while the bug is being fixed. Which approach is most effective?
Select an answer first - 7
A company is migrating its on-premises web application to Azure. The application currently uses forms-based authentication with a session cookie. The security team wants to reduce the risk of session hijacking and also support single sign-on with Microsoft 365. Which authentication approach should they adopt?
Select an answer first - 8
A multi-tenant SaaS application allows users to upload files. The application uses a shared storage bucket and generates file URLs that include the tenant ID and file name. A security researcher discovers that by changing the tenant ID in the URL, they can access files belonging to another tenant. The application uses a single shared storage account. What is the most effective mitigation?
Select an answer first - 9
A healthcare portal is experiencing a brute-force attack on its admin login page. The security team wants to block automated attempts while minimizing impact on legitimate users. They also need to comply with a policy that prohibits permanent account lockouts. Which approach best balances security and usability?
Select an answer first - 10
A company's web application uses cookie-based authentication. The security team wants to reduce the risk of session hijacking via cross-site scripting (XSS). Which configuration should be applied to the session cookie?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.