
EC-CouncilCertified Application Security Engineer (.NET)
Domain 7Objective 2
Defensive Coding Against Information Disclosure CASENET Practice Questions (Page 1)
Part of the Secure Coding: Error Handling and Logging domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
10concepts
Questions 1–5
- 1
A team uses Serilog in an ASP.NET Core application. They need to log exceptions for debugging but must ensure that passwords and credit card numbers never appear in log files. Which configuration should they use?
Select an answer first - 2
What is the primary purpose of centralized error logging?
Select an answer first - 3
A development team is using Serilog in an ASP.NET Core application. They want to ensure that no sensitive data, such as passwords or credit card numbers, is written to logs. Which Serilog feature should they use?
Select an answer first - 4
An attacker triggers an unhandled exception and sees a detailed error page with file paths and SQL query fragments. What is the primary security impact?
Select an answer first - 5
A .NET Framework web application has a global exception handler in Global.asax. Currently, the Application_Error method writes the exception details to the response. You need to change it so that users see a generic message but developers can still get details. What should you do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.