Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 2Objective 6

Secure Design Principles CASENET Practice Questions (Page 6)

Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
6concepts

Questions 26–30

  1. 26application · medium

    A .NET developer is new to threat modeling and asks a senior colleague: 'We have a data flow diagram and a list of assets. What is the next step to systematically identify threats?' Which response best reflects the core threat modeling fundamentals?

    Select an answer first
  2. 27expert · hard

    A .NET application is being designed for a healthcare organization. It will allow patients to book appointments and view their medical records. The system will be accessed via a public web portal and an internal staff portal. The team is conducting a threat modeling session. They have identified the following assets: patient PII, medical records, and appointment data. They have created a data flow diagram showing the public portal sending appointment requests to a booking service, which writes to a database. The staff portal reads from the same database. The team is now at the point of prioritizing threats. They have limited time and must focus on the most critical threats. Which approach best aligns with the threat modeling process while considering the time constraint?

    Select an answer first
  3. 28foundation · easy

    Which mitigation strategy is most effective for preventing unauthorized users from accessing restricted pages in a .NET MVC application?

    Select an answer first
  4. 29foundation · easy

    A .NET application runs a background service that only needs to read from a specific database table. According to the principle of least privilege, how should the service's database account be configured?

    Select an answer first
  5. 30foundation · easy

    In a structured threat modeling process, which step typically follows the creation of a data flow diagram?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.