
EC-CouncilCertified Application Security Engineer (.NET)
Domain 2Objective 4
OCTAVE CASENET Practice Questions (Page 9)
Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
8concepts
Questions 41–45
- 41
A manufacturing company is performing an OCTAVE technological view. The team is reviewing the SCADA system that controls production. They find that the system runs on an outdated operating system and that vendor patches are not applied regularly. What is the most appropriate way to document these findings?
Select an answer first - 42
An OCTAVE assessment team has identified a threat scenario where an attacker exploits a SQL injection vulnerability in a .NET web application to access a customer database. The team rates the likelihood as high and the impact as severe. According to OCTAVE, what should the team do next?
Select an answer first - 43
In OCTAVE risk analysis, what two factors are primarily evaluated to determine risk?
Select an answer first - 44
An OCTAVE team is analyzing risks for a .NET application that provides online banking services. They identify two threat scenarios: (1) a distributed denial-of-service (DDoS) attack that could make the service unavailable, and (2) a SQL injection vulnerability that could expose customer account data. The team has limited resources and must decide which risk to address first. What should they do?
Select an answer first - 45
A fintech startup is conducting an OCTAVE assessment for its .NET-based payment processing platform. The platform handles cardholder data and is subject to PCI DSS. The team has identified two major threat scenarios: (1) an external attacker exploiting a known vulnerability in a third-party component to steal card data, and (2) an insider abusing privileged access to modify transaction records. The external attack has a high likelihood and high impact; the insider threat has low likelihood but very high impact. The company has limited budget and must prioritize mitigation. Which approach best aligns with OCTAVE's risk analysis and mitigation strategy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.