Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 5Objective 4

Cryptographic Attacks CASENET Practice Questions (Page 8)

Part of the Secure Coding: Cryptography domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
3concepts

Questions 36–40

  1. 36application · medium

    A .NET application uses a padding oracle vulnerability in its CBC-mode decryption routine. An attacker can send modified ciphertexts to an error endpoint that reveals whether padding is valid. The team must fix the vulnerability without breaking existing encrypted data. Which remediation should they implement?

    Select an answer first
  2. 37foundation · easy

    A .NET application uses CBC-mode encryption and returns detailed error messages when padding is invalid. Which countermeasure would best mitigate a padding oracle attack?

    Select an answer first
  3. 38expert · hard

    A .NET application uses a custom protocol that encrypts messages with AES-CBC and then applies HMAC-SHA256 to the ciphertext. The developer implemented the HMAC key as the same AES key. A cryptanalyst points out that this is a key-reuse flaw. What is the most secure alternative that still provides both confidentiality and integrity?

    Select an answer first
  4. 39foundation · easy

    A penetration tester captures a set of password hashes from a .NET web application. The tester wants to recover the plaintext passwords by precomputing hash chains and storing them in a large lookup table. Which type of cryptographic attack is the tester performing?

    Select an answer first
  5. 40application · medium

    A .NET application uses a hard-coded AES key in the binary. The key was extracted by an attacker, and the application now needs to be fixed. Which solution provides the strongest protection for the key?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CASENET

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.