Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 2Objective 6

Secure Design Principles CASENET Practice Questions (Page 1)

Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
6concepts

Questions 1–5

  1. 1application · medium

    A team is conducting a threat modeling exercise for a .NET application that handles sensitive customer data. They have created a data flow diagram and identified trust boundaries. Which of the following is the most important next step to ensure the threat model is comprehensive?

    Select an answer first
  2. 2expert · hard

    A team is threat modeling a .NET application that handles financial transactions. They have limited resources and need to prioritize threats for mitigation. Which approach best aligns with a structured threat modeling process?

    Select an answer first
  3. 3expert · hard

    A .NET application has an API endpoint that allows users to update their profile information. The endpoint is vulnerable to authorization flaws, allowing users to modify other users' profiles. The team wants to implement a mitigation that follows secure design principles. Which approach is the most effective?

    Select an answer first
  4. 4application · medium

    A .NET application uses a single service account to connect to both the application database and the logging database. The application also exposes a debug endpoint that is enabled in production. The team wants to apply the principle of least privilege and fail-safe defaults. Which change best aligns with these principles?

    Select an answer first
  5. 5application · medium

    A .NET application has a password reset feature that sends a reset link to the user's email. The link contains a token that is valid for 24 hours. The security team wants to mitigate the threat of token theft and replay. Which mitigation strategy should be applied?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.