Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 2Objective 6

Secure Design Principles CASENET Practice Questions (Page 9)

Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
6concepts

Questions 41–45

  1. 41application · medium

    A .NET web application is being redesigned. Currently, it exposes several administrative endpoints that are not used by any legitimate feature. The application also has a public search feature that accepts a 'q' parameter and reflects it in the page without encoding. The team wants to reduce the attack surface and address the reflected XSS issue. Which approach best achieves both goals?

    Select an answer first
  2. 42application · medium

    A team is starting a threat modeling exercise for a new .NET application. They have limited time and need to focus on the most critical areas. Which approach best aligns with core threat modeling fundamentals?

    Select an answer first
  3. 43foundation · easy

    A .NET web application stores user passwords in plain text in a database. An attacker who gains access to the database can read all passwords. Which STRIDE category best describes this threat?

    Select an answer first
  4. 44expert · hard

    A .NET application is being developed for a financial institution. The application will be accessed by customers and internal staff. The team is conducting a threat modeling session and has identified the following assets: account balances, transaction history, and customer credentials. They have created a data flow diagram showing the customer portal sending transaction requests to a core banking system, which updates a database. The internal staff portal also accesses the same database. The team has limited time and must prioritize threats. Which threat should be considered the highest priority based on the assets and data flows?

    Select an answer first
  5. 45expert · hard

    A .NET application exposes a public API that accepts JSON payloads. The API is used by multiple clients with different trust levels. The team wants to mitigate injection attacks while maintaining performance and usability. Which approach best balances security and functionality?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.