
EC-CouncilCertified Application Security Engineer (.NET)
Domain 8Objective 2
Dynamic Application Security Testing (DAST) CASENET Practice Questions (Page 4)
Part of the Security Testing and Secure Deployment domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
8concepts
Questions 16–20
- 16
A DAST scan report shows a critical SQL injection vulnerability in a search endpoint. The development team has already fixed the issue and deployed the fix to production. The security team wants to confirm the fix. What is the most reliable way to verify the remediation?
Select an answer first - 17
At which stage of the SDLC is DAST most effectively integrated to provide continuous security testing?
Select an answer first - 18
A DAST scan of a .NET application reports a reflected XSS vulnerability in a search results page. The development team wants to confirm the finding before fixing it. Which action best validates the DAST result?
Select an answer first - 19
When analyzing a DAST scan report, which factor should be prioritized when deciding which vulnerability to remediate first?
Select an answer first - 20
A DAST scan is being configured for a .NET application that uses a search feature with a parameter called 'q'. The scanner is not testing the search parameter with malicious payloads. Which technique should be used to ensure the parameter is fuzzed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.