Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 6Objective 2

Cookie-Based Session Management CASENET Practice Questions (Page 6)

Part of the Secure Coding: Session Management domain, which makes up ~10% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
10concepts

Questions 26–30

  1. 26foundation · easy

    Which ASP.NET configuration setting controls the session idle timeout?

    Select an answer first
  2. 27foundation · easy

    Which of the following best describes the structure of a cookie?

    Select an answer first
  3. 28application · medium

    An ASP.NET application stores the username and a role claim directly in the session cookie. A security review notes that users can modify the cookie and escalate privileges. Which approach should be used to protect the cookie's integrity?

    Select an answer first
  4. 29application · medium

    A financial application stores the user's account number and role directly in the session cookie. The security team requires that the cookie's contents remain confidential and that any tampering with the values be detected. The application runs on ASP.NET Core. Which configuration should the developer use?

    Select an answer first
  5. 30foundation · easy

    What is a key requirement for a secure session identifier?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.