
EC-CouncilCertified Application Security Engineer (.NET)
Domain 2Objective 4
OCTAVE CASENET Practice Questions (Page 10)
Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
8concepts
Questions 46–50
- 46
In the OCTAVE methodology, what is the focus of the vulnerability assessment step?
Select an answer first - 47
An OCTAVE assessment team is evaluating a .NET application that uses a custom authentication module. The team finds that the module has a vulnerability that allows brute-force attacks. The team also notes that the application is exposed to the internet. The team must decide on a mitigation strategy. What is the most effective approach?
Select an answer first - 48
Which phase of the SDLC would benefit most from applying OCTAVE risk assessment principles?
Select an answer first - 49
During an OCTAVE assessment for a .NET e-commerce application, the team identifies that the application stores customer payment card data. They are now analyzing potential threat sources. Which threat source and motivation pairing is most relevant to this asset?
Select an answer first - 50
An insurance company is conducting an OCTAVE risk analysis. The team has identified a threat scenario where a phishing attack could lead to unauthorized access to customer policy data. The likelihood is rated high because employees frequently click on suspicious links, and the impact is rated high because of regulatory penalties. What should the team do next?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.