
EC-CouncilCertified Application Security Engineer (.NET)
Domain 7Objective 2
Defensive Coding Against Information Disclosure CASENET Practice Questions (Page 6)
Part of the Secure Coding: Error Handling and Logging domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
10concepts
Questions 26–30
- 26
Which of the following is a direct information disclosure risk caused by improper error handling?
Select an answer first - 27
Your organization's security policy requires that application logs be stored for at least one year and that only the security team can access them. The logs contain error details that might include sensitive information. Which storage solution best meets these requirements?
Select an answer first - 28
A .NET web application returns detailed exception messages to users, including stack traces and SQL query fragments. The security team has mandated that users must only see a generic message, while developers need full details for debugging. What should you implement?
Select an answer first - 29
Which practice best supports centralized error logging while protecting sensitive information?
Select an answer first - 30
During a code review, you notice that a logging statement in a .NET application writes the entire exception object, which includes the password reset token in the message. What is the most effective way to prevent this sensitive data from being logged?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.