Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 2Objective 7

Secure Application Architecture CASENET Practice Questions (Page 10)

Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
9concepts

Questions 46–50

  1. 46expert · hard

    A .NET web application uses session-based authentication. The security team wants to prevent session fixation attacks. Which combination of controls should be implemented?

    Select an answer first
  2. 47application · medium

    A healthcare .NET application stores patient records in a SQL Server database. The compliance team requires that patient data be unreadable if the database files are stolen, but the application must still be able to search by patient name. The data is currently stored in plaintext. Which data protection strategy should the architect implement?

    Select an answer first
  3. 48expert · hard

    A .NET application has a three-tier architecture: presentation, business, and data. The threat model identifies that a SQL injection vulnerability exists in the data layer. The business layer also trusts the presentation layer for authorization decisions. The security team must implement a fix. Which approach best addresses the root cause?

    Select an answer first
  4. 49foundation · easy

    In the STRIDE threat model, which threat category involves an attacker reading data that they are not authorized to access?

    Select an answer first
  5. 50application · medium

    A .NET application communicates with a third-party payment gateway over the internet. The payment gateway supports TLS 1.2 and TLS 1.3. The security policy requires that all data in transit be encrypted and that the connection resist downgrade attacks. What should the architect configure?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.