
EC-CouncilCertified Application Security Engineer (.NET)
Domain 2Objective 7
Secure Application Architecture CASENET Practice Questions (Page 6)
Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
9concepts
Questions 26–30
- 26
During a threat modeling exercise for a .NET web application, the team uses the STRIDE model. They identify that an attacker could tamper with the application's session cookie to escalate privileges. Which STRIDE category does this threat fall under, and what is the primary mitigation?
Select an answer first - 27
A .NET application stores sensitive documents in Azure Blob Storage. The application uses a shared access signature (SAS) to allow users to download files. The security team is concerned that a leaked SAS URL could be used by an attacker to access all files in the container. Which approach should be used to limit the impact of a leaked SAS?
Select an answer first - 28
A .NET e-commerce application stores user passwords in a SQL Server database. The security team requires that passwords be protected even if the database is compromised. The application must also prevent attackers from using the same password across multiple user accounts. Which approach should the architect implement?
Select an answer first - 29
A .NET application uses a REST API that is publicly accessible. The threat model identifies that an attacker could perform a man-in-the-middle attack to intercept and modify API responses. The application currently uses HTTPS but does not enforce certificate pinning. The team is considering adding certificate pinning to the mobile client. However, the API is also consumed by a web application that cannot easily implement pinning. What is the best approach to mitigate the risk?
Select an answer first - 30
A .NET application is deployed on a single web server with a SQL Server database on the same host. The security team wants to apply the principle of defense in depth. Which change best reflects this principle?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.