Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 6Objective 2

Cookie-Based Session Management CASENET Practice Questions (Page 2)

Part of the Secure Coding: Session Management domain, which makes up ~10% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
10concepts

Questions 6–10

  1. 6foundation · easy

    What is the primary purpose of an HTTP cookie in the context of session management?

    Select an answer first
  2. 7application · medium

    An online banking application currently keeps sessions active indefinitely as long as the browser is open. A security audit recommends limiting the window during which a stolen session cookie can be used. The application must also allow users to remain logged in while actively performing transactions. Which session expiration policy should the developer implement?

    Select an answer first
  3. 8foundation · easy

    Which of the following is an effective technique to mitigate session hijacking?

    Select an answer first
  4. 9foundation · easy

    What is the primary purpose of encrypting session cookies?

    Select an answer first
  5. 10foundation · easy

    What is the primary defense against session fixation attacks?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.