
EC-CouncilCertified Application Security Engineer (.NET)
Domain 8Objective 2
Dynamic Application Security Testing (DAST) CASENET Practice Questions (Page 8)
Part of the Security Testing and Secure Deployment domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
8concepts
Questions 36–40
- 36
A DAST scan of a single-page application (SPA) built with Angular is not discovering vulnerabilities in client-side rendered views. The scanner only sees the initial HTML shell. Which technique should be used to improve DAST coverage of the SPA?
Select an answer first - 37
A security team is preparing to run DAST on a .NET application that has multiple user roles: anonymous, standard user, and administrator. The application's functionality varies significantly by role. What is the best practice for scoping the scan to ensure comprehensive coverage?
Select an answer first - 38
Which statement correctly contrasts SAST and DAST?
Select an answer first - 39
After running a DAST scan on a .NET web application, the report lists a potential SQL injection in a search parameter and a potential XSS in a comment field. The security team needs to prioritize remediation. Which finding should be addressed first?
Select an answer first - 40
A security architect is evaluating whether to use DAST for a .NET application that is a REST API with no user interface. The API uses token-based authentication and is consumed by mobile clients. Which consideration is most important when deciding to use DAST for this API?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.