
EC-CouncilCertified Application Security Engineer (.NET)
Domain 2Objective 6
Secure Design Principles CASENET Practice Questions (Page 7)
Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
6concepts
Questions 31–35
- 31
A .NET application is being redesigned to use a microservices architecture. Each microservice has its own database. The security team wants to apply the principle of least privilege across the services. Which approach is the most appropriate?
Select an answer first - 32
A team is threat modeling a .NET application that allows users to upload and share documents. The application has a web front end, a file storage service, and a metadata database. The team has identified the following assets: user documents, metadata, and authentication credentials. They have created a data flow diagram showing the web front end accepting uploads, storing files in the storage service, and writing metadata to the database. During the session, they want to prioritize threats. Which step should they perform first to ensure a structured process?
Select an answer first - 33
A team is threat modeling a .NET application that will be deployed in a hybrid cloud environment. The application will process data that is subject to data residency requirements. The team needs to identify threats related to data flows. Which approach best addresses the data residency concern?
Select an answer first - 34
Which secure design principle is best illustrated by a .NET application that uses multiple layers of security controls, such as input validation, authentication, and output encoding, to protect against attacks?
Select an answer first - 35
A team is conducting a threat modeling session for a new .NET microservices-based order processing system. The system includes a public-facing web API, an internal order service, a message queue, and a legacy SQL database. The team has identified the following assets: customer PII, order details, and payment card data. They have drawn a data flow diagram showing the web API receiving orders, placing messages on the queue, and the order service consuming messages and updating the database. During the session, they want to prioritize threats. Which approach best aligns with the structured threat modeling process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.