Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 2Objective 6

Secure Design Principles CASENET Practice Questions (Page 10)

Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
6concepts

Questions 46–48

  1. 46expert · hard

    A .NET application has a public-facing search feature that queries a database. The search feature is essential for the business. The team wants to reduce the attack surface while maintaining the feature. Which approach is the most appropriate?

    Select an answer first
  2. 47application · medium

    A .NET web application has a login form that is vulnerable to brute-force attacks. The team wants to implement a mitigation that aligns with defense in depth. Which combination of controls should they implement?

    Select an answer first
  3. 48expert · hard

    A .NET application has a legacy admin module that is only used by a few internal users. The module is currently accessible from the internet. The team wants to reduce the attack surface without breaking functionality. Which approach is the most effective?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CASENET

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.