
EC-CouncilCertified Application Security Engineer (.NET)
Domain 4Objective 1
Common Threats on User Authentication and Authorization CASENET Practice Questions (Page 3)
Part of the Secure Coding: Authentication and Authorization domain, which makes up ~7% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
Questions 11–15
- 11
An organization is implementing a new web application that will handle sensitive customer data. The security team wants to mitigate the risk of brute force attacks on the login form. Which combination of controls is most effective?
Select an answer first - 12
An organization wants to implement a password policy that resists brute-force and credential-stuffing attacks. Which combination of controls is most effective?
Select an answer first - 13
Which of the following is a potential business impact of a successful credential stuffing attack on a web application?
Select an answer first - 14
Which authorization threat occurs when an attacker directly requests a restricted URL (e.g., '/admin/settings') that is not linked in the UI but is still accessible without proper authorization checks?
Select an answer first - 15
A web application has an admin panel that is not linked in the UI. A security test reveals that any authenticated user can access the admin panel by directly entering the URL /admin. The application uses role-based access control, and the 'Admin' role is the only role that should access the panel. What is the most appropriate fix?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.