Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 2Objective 6

Secure Design Principles CASENET Practice Questions (Page 8)

Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
6concepts

Questions 36–40

  1. 36application · medium

    A .NET application uses a custom authentication module that sets a FormsAuthentication cookie after verifying the user's credentials. The security team is concerned about session hijacking. Which mitigation strategy should be applied to directly address the threat of session hijacking via cookie theft?

    Select an answer first
  2. 37application · medium

    A .NET web application allows users to upload profile pictures. The development team is implementing the upload feature and wants to prevent spoofing and tampering risks. They plan to store files in a dedicated folder and serve them via a separate handler. Which combination of controls should they implement to align with secure design principles?

    Select an answer first
  3. 38foundation · easy

    In the STRIDE threat model, which category covers an attacker modifying data in transit between a .NET client and server?

    Select an answer first
  4. 39application · medium

    A .NET application has multiple entry points, including a public website, an API for mobile clients, and an internal admin panel. The security team is performing an attack surface analysis. Which action should they take to reduce the attack surface?

    Select an answer first
  5. 40application · medium

    A team is threat modeling a new .NET microservice that processes payment transactions. They have identified the assets and drawn a data flow diagram. Which next step should they take to ensure the threat model is actionable?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.