Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 2Objective 7

Secure Application Architecture CASENET Practice Questions (Page 4)

Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
9concepts

Questions 16–20

  1. 16expert · hard

    A .NET API uses OAuth 2.0 with the authorization code flow. The API is a resource server that validates access tokens. The security team wants to ensure that a compromised client application cannot access another client's data. Which control should be implemented?

    Select an answer first
  2. 17application · medium

    A .NET web application is deployed behind an Azure Application Gateway. The application uses HTTP for internal service-to-service calls between the web tier and the business tier. The security team wants to ensure all traffic is encrypted. What should be configured?

    Select an answer first
  3. 18application · medium

    A .NET e-commerce application uses a three-tier architecture. During a threat modeling session, the team identifies that the presentation layer directly constructs SQL queries using user-supplied search text, and the business layer trusts the presentation layer's user ID without re-authentication. The data layer stores credit card numbers in plaintext. Which combination of security controls should the architect prioritize to address the most critical risks across all layers?

    Select an answer first
  4. 19foundation · easy

    What is the primary purpose of validating input in an API endpoint?

    Select an answer first
  5. 20foundation · easy

    Which security design pattern is most effective in preventing sensitive information leakage through verbose error messages?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.