
EC-CouncilCertified Application Security Engineer (.NET)
Domain 4Objective 1
Common Threats on User Authentication and Authorization CASENET Practice Questions (Page 7)
Part of the Secure Coding: Authentication and Authorization domain, which makes up ~7% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
Questions 31–35
- 31
A security analyst is assessing the impact of a session hijacking vulnerability in a web application. The application uses session cookies without the Secure flag, and the site is accessible over both HTTP and HTTPS. An attacker on the same network uses a tool to intercept HTTP traffic and steals a session cookie. What is the most significant impact of this vulnerability?
Select an answer first - 32
A banking application allows users to transfer funds. The application uses a session cookie that is not marked HttpOnly, and the site has a stored XSS vulnerability in the user profile field. An attacker crafts a malicious script that, when executed in a victim's browser, sends the session cookie to the attacker's server. What is the most likely impact of this attack?
Select an answer first - 33
An attacker collects username and password pairs from a previous data breach and tries them against a web application's login page. Which authentication threat does this describe?
Select an answer first - 34
A web application uses cookie-based sessions. The security team wants to mitigate the risk of session hijacking via network eavesdropping. Which configuration should be applied to the session cookie?
Select an answer first - 35
A project management tool has a feature where users can view their own tasks by navigating to /tasks/{taskId}. A security review finds that any authenticated user can access tasks belonging to other users by simply changing the taskId in the URL. The application uses role-based access control, and the 'User' role is supposed to only access their own tasks. What is the most appropriate fix?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.