Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 2Objective 6

Secure Design Principles CASENET Practice Questions (Page 3)

Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
6concepts

Questions 11–15

  1. 11application · medium

    A .NET application has a feature that allows users to export reports. The export function runs with elevated privileges to access a shared network folder. The security team wants to apply the principle of least privilege. What should they do?

    Select an answer first
  2. 12application · medium

    A .NET application exposes an administrative API that is currently accessible from the public internet. The API includes endpoints for user management and configuration changes. The security team wants to reduce the attack surface while maintaining necessary functionality. Which approach best achieves this?

    Select an answer first
  3. 13application · medium

    A .NET MVC application has an endpoint that allows authenticated users to upload profile pictures. The endpoint accepts any file extension and stores files in the web root under /uploads. The development team wants to minimize the attack surface for this feature. Which combination of changes best reduces the attack surface while maintaining functionality?

    Select an answer first
  4. 14foundation · easy

    Which action is most effective in reducing the attack surface of a .NET web application?

    Select an answer first
  5. 15application · medium

    A .NET application allows users to upload files that are then processed by a background service. The team is threat modeling and identifies a threat where an attacker uploads a file with a malicious payload that is executed by the processing service. Which STRIDE category does this threat belong to, and what is the most appropriate mitigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.