
EC-CouncilCertified Application Security Engineer (.NET)
Domain 7Objective 3
Secure Auditing and Logging CASENET Practice Questions (Page 2)
Part of the Secure Coding: Error Handling and Logging domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
8concepts
Questions 6–10
- 6
What is the primary risk of logging sensitive data such as credit card numbers or passwords?
Select an answer first - 7
A development team is configuring Serilog for an ASP.NET Core application. They want to log security-relevant events such as login failures and authorization denials, but they are concerned about performance and log volume. Which configuration approach best meets these needs?
Select an answer first - 8
Which measure helps protect logs from unauthorized access or modification?
Select an answer first - 9
A company's compliance policy requires that audit logs be retained for at least one year and be resistant to tampering. The current .NET application writes logs to a local file. What is the most effective way to meet these requirements?
Select an answer first - 10
A security analyst is reviewing logs from a .NET application and notices that the logs contain many entries from a single IP address that are not related to any user action. The entries are all at Information level and appear to be automated health checks. The analyst wants to reduce noise in the logs to focus on security events. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.