Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 2Objective 6

Secure Design Principles CASENET Practice Questions (Page 4)

Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
6concepts

Questions 16–20

  1. 16foundation · easy

    When analyzing the attack surface of a .NET application, which of the following should be considered an entry point?

    Select an answer first
  2. 17expert · hard

    A .NET application has a feature that allows users to export their data as a CSV file. The export is generated on the server and stored in a temporary folder, then served to the user via a link. The application uses a shared hosting environment where multiple applications run under the same service account. The security team has identified a threat: an attacker could potentially access another user's exported file by guessing the filename. Which STRIDE category best describes this threat, and which mitigation is most appropriate?

    Select an answer first
  3. 18expert · hard

    A team is threat modeling a .NET application that processes credit card payments. The application has a web front end, a payment processing service, and a database that stores transaction logs. The team has identified the following assets: cardholder data, transaction logs, and encryption keys. They have created a data flow diagram showing the web front end sending payment details to the payment service, which encrypts the data and stores it in the database. During the session, they identify a threat: an attacker could tamper with the transaction amount before it is encrypted. Which step in the threat modeling process should the team take next to address this threat?

    Select an answer first
  4. 19application · medium

    A .NET web application exposes an administrative dashboard that is used by a small team of IT staff. The dashboard is on the same IIS site as the public-facing customer portal. During a threat modeling session, the team identifies that if an attacker compromises a low-privileged customer account, they could potentially access the admin dashboard due to shared application pools. Which design change best applies the principle of least privilege and reduces the attack surface?

    Select an answer first
  5. 20foundation · easy

    Which statement best describes the role of trust boundaries in a threat model for a .NET application?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.