Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 8Objective 3

Secure Deployment at Host, Network, and Application Levels CASENET Practice Questions (Page 1)

Part of the Security Testing and Secure Deployment domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
7concepts

Questions 1–5

  1. 1application · medium

    A company is deploying a .NET web application to a new Windows Server 2022 host that will be exposed to the internet. The security team requires that the host be hardened before the application is installed. Which action should be taken FIRST to reduce the attack surface?

    Select an answer first
  2. 2expert · hard

    A .NET application is deployed in a hybrid cloud environment. The web tier is in a public cloud, and the database tier is on-premises. The security team requires that the database tier not be exposed to the internet. What is the most secure way to connect the web tier to the database tier?

    Select an answer first
  3. 3application · medium

    A .NET web application uses Windows authentication and is deployed to an intranet. The security team wants to ensure that only authorized users can access the application. Which configuration should be applied?

    Select an answer first
  4. 4expert · hard

    A .NET application is deployed in a multi-tier environment. The security team wants to ensure that the web server can only communicate with the application server, and the application server can only communicate with the database server. What is the best way to enforce this?

    Select an answer first
  5. 5application · medium

    A .NET application is deployed in a cloud environment. The application communicates with a backend API over HTTPS. The security team requires that the communication between the web server and the API server be encrypted. Which control should be implemented?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.