
EC-CouncilCertified Application Security Engineer (.NET)
Domain 2Objective 4
OCTAVE CASENET Practice Questions (Page 6)
Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
8concepts
Questions 26–30
- 26
A utility company is conducting an OCTAVE assessment. The team has completed the organizational view and is now in the technological view. They have identified that the customer billing system has a known vulnerability in its authentication module. What is the most appropriate action in this phase?
Select an answer first - 27
According to OCTAVE, which of the following is considered a critical information asset?
Select an answer first - 28
An OCTAVE assessment team is working with a healthcare organization that stores electronic health records (EHRs). The team must identify critical assets and their relative importance. The organization has multiple systems, including the EHR system, a research database, and a public website. The team has limited time and must prioritize which asset to focus on. What should they do?
Select an answer first - 29
An e-commerce company is starting an OCTAVE assessment. The security team has listed several information assets: customer PII, payment card data, marketing analytics, and internal employee emails. The team must prioritize these assets for the risk assessment. Which asset should be treated as the most critical, and why?
Select an answer first - 30
A defense contractor is conducting an OCTAVE assessment for its .NET-based project management system, which contains classified project data. The team identifies two threat scenarios: (1) a foreign intelligence service using spear-phishing to steal credentials, and (2) a malicious insider with legitimate access exfiltrating data via USB. The external threat has moderate likelihood and high impact; the insider threat has low likelihood but catastrophic impact. The company must decide where to invest limited security budget. Which decision best reflects OCTAVE's risk analysis and mitigation strategy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.