
EC-CouncilCertified Application Security Engineer (.NET)
Domain 3Objective 1
Input Validation Approaches and Filtering CASENET Practice Questions (Page 2)
Part of the Secure Coding: Input Validation domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 2–2 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
9concepts
Questions 6–10
- 6
What is the purpose of output encoding in the context of input validation?
Select an answer first - 7
A .NET application has a form field for a US ZIP code. The team needs to validate the input. Which validation approach is most appropriate?
Select an answer first - 8
Why is server-side validation essential even when client-side validation is implemented?
Select an answer first - 9
A .NET application has a dropdown list of country codes (e.g., US, CA, MX). The selected value is posted to the server. What is the best way to validate the posted value?
Select an answer first - 10
A .NET web application accepts a product code from a query string and uses it to look up a record in a database. The product code must be exactly 8 characters: 3 uppercase letters followed by 5 digits. The developer wants to enforce this with minimal code and prevent SQL injection. What is the most appropriate validation approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.