
EC-CouncilCertified Application Security Engineer (.NET)
Domain 8Objective 2
Dynamic Application Security Testing (DAST) CASENET Practice Questions (Page 2)
Part of the Security Testing and Secure Deployment domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
8concepts
Questions 6–10
- 6
Which of the following is a known limitation of DAST?
Select an answer first - 7
A DAST scan of a .NET application reports a high number of SQL injection alerts, but the development team insists the application uses parameterized queries everywhere. What is the most likely cause of these false positives?
Select an answer first - 8
A DAST scan report lists a potential SQL injection vulnerability with a 'High' severity, but the security team has limited resources and must decide which findings to remediate first. The report also includes several 'Medium' XSS findings and a 'Low' information disclosure finding. How should the team prioritize?
Select an answer first - 9
A DAST scanner is configured to test a .NET web application. The scanner has completed crawling and is now sending unexpected input to various parameters to see if the application handles it securely. Which DAST technique is being used?
Select an answer first - 10
A company wants to integrate DAST into its CI/CD pipeline but is concerned about scan time and false positives blocking releases. The application is large and has many endpoints. Which strategy best balances security testing with release velocity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.