
EC-CouncilCertified Application Security Engineer (.NET)
Domain 2Objective 7
Secure Application Architecture CASENET Practice Questions (Page 8)
Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
9concepts
Questions 36–40
- 36
A .NET application uses a message queue to process orders. The security team is performing a threat model and identifies that an attacker could inject malicious messages into the queue, causing the order processing service to execute unintended actions. Which control should be prioritized?
Select an answer first - 37
Which protocol is the standard for encrypting HTTP traffic to protect data in transit between a web browser and a web server?
Select an answer first - 38
In a layered application architecture, which layer is primarily responsible for enforcing authorization rules and orchestrating business operations?
Select an answer first - 39
A .NET API is consumed by a mobile app and a third-party partner. The API currently accepts requests with a static API key in the header. The security team wants to improve authentication and authorization. Which approach should be implemented?
Select an answer first - 40
A .NET application is deployed using a CI/CD pipeline. The security team wants to ensure that production configuration secrets (e.g., connection strings, API keys) are not exposed in the source code repository. Which practice should be adopted?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.