
EC-CouncilCertified Application Security Engineer (.NET)
Domain 4Objective 1
Common Threats on User Authentication and Authorization CASENET Practice Questions (Page 5)
Part of the Secure Coding: Authentication and Authorization domain, which makes up ~7% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
Questions 21–25
- 21
A web application allows users to log in and then navigate to different pages. After login, the application sets a session cookie but does not set the Secure or HttpOnly flags. An attacker exploits a stored XSS vulnerability to steal the cookie. Which threat has occurred, and which mitigation would have prevented it?
Select an answer first - 22
Which authentication threat occurs when an attacker intercepts a valid session token and uses it to impersonate the legitimate user?
Select an answer first - 23
A security analyst is assessing the impact of a credential stuffing attack on a web application. The application has multi-factor authentication (MFA) enabled for all users. What is the most likely impact of the attack?
Select an answer first - 24
What is the most significant potential impact of a successful privilege escalation attack on a web application?
Select an answer first - 25
A company's web application allows users to log in with their email and password. The security team is concerned about credential stuffing attacks. Which additional control would be most effective in preventing attackers from using stolen credentials?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.