Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 7Objective 3

Secure Auditing and Logging CASENET Practice Questions (Page 9)

Part of the Secure Coding: Error Handling and Logging domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
8concepts

Questions 41–45

  1. 41foundation · easy

    What is the purpose of setting up monitoring and alerting based on application logs?

    Select an answer first
  2. 42expert · hard

    A healthcare organization's .NET application must log access to patient records. The audit trail must support investigations, but the organization also has a strict data minimization policy. The logs are stored for two years. Which approach best balances auditability with data minimization?

    Select an answer first
  3. 43application · medium

    A .NET application's global exception handler logs the exception object directly. The security review found that exception messages sometimes contain SQL query parameters, including user input. The team wants to keep the exception details for debugging but prevent sensitive data from being logged. What is the best approach?

    Select an answer first
  4. 44application · medium

    A .NET web application logs exception details using a custom middleware that serializes the exception object. During a security review, you discover that stack traces and inner exception messages are being written to the application log file. The application handles credit card numbers in request bodies. Which change best reduces the risk of sensitive data leakage while preserving useful diagnostic information?

    Select an answer first
  5. 45expert · hard

    A .NET application logs exceptions using a third-party logging library. The library automatically logs the exception's Data dictionary, which sometimes contains sensitive values added by the application. The team wants to keep the Data dictionary for debugging but prevent sensitive data from being logged. What is the best approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.