Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 4Objective 1

Common Threats on User Authentication and Authorization CASENET Practice Questions (Page 7)

Part of the Secure Coding: Authentication and Authorization domain, which makes up ~7% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
4concepts

Questions 31–35

  1. 31expert · hard

    A security analyst is assessing the impact of a session hijacking vulnerability in a web application. The application uses session cookies without the Secure flag, and the site is accessible over both HTTP and HTTPS. An attacker on the same network uses a tool to intercept HTTP traffic and steals a session cookie. What is the most significant impact of this vulnerability?

    Select an answer first
  2. 32expert · hard

    A banking application allows users to transfer funds. The application uses a session cookie that is not marked HttpOnly, and the site has a stored XSS vulnerability in the user profile field. An attacker crafts a malicious script that, when executed in a victim's browser, sends the session cookie to the attacker's server. What is the most likely impact of this attack?

    Select an answer first
  3. 33foundation · easy

    An attacker collects username and password pairs from a previous data breach and tries them against a web application's login page. Which authentication threat does this describe?

    Select an answer first
  4. 34application · medium

    A web application uses cookie-based sessions. The security team wants to mitigate the risk of session hijacking via network eavesdropping. Which configuration should be applied to the session cookie?

    Select an answer first
  5. 35application · medium

    A project management tool has a feature where users can view their own tasks by navigating to /tasks/{taskId}. A security review finds that any authenticated user can access tasks belonging to other users by simply changing the taskId in the URL. The application uses role-based access control, and the 'User' role is supposed to only access their own tasks. What is the most appropriate fix?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.