Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 8Objective 5

Security Maintenance and Monitoring CASENET Practice Questions (Page 1)

Part of the Security Testing and Secure Deployment domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
6concepts

Questions 1–5

  1. 1application · medium

    A healthcare organization must log all authentication events for its ASP.NET Core application to meet HIPAA requirements. The application uses Azure AD for authentication. Which logging configuration is most appropriate?

    Select an answer first
  2. 2application · medium

    A development team uses a .NET Core application with several NuGet packages. A vulnerability scan flags a critical flaw in a transitive dependency. The team wants to remediate quickly. What is the most appropriate first step?

    Select an answer first
  3. 3expert · hard

    A .NET application was compromised. The incident response team found that the attacker used a previously unknown vulnerability in a custom library. The team has limited time to restore service. They must decide between restoring from a backup taken before the attack or applying a hotfix to the current system. Which decision is most appropriate?

    Select an answer first
  4. 4application · medium

    A multinational company's .NET application processes personal data of EU citizens. The compliance officer requires that security maintenance activities be documented to demonstrate GDPR compliance. What is the most important documentation to maintain?

    Select an answer first
  5. 5application · medium

    A development team uses .NET Core 3.1, which is out of support. The application is deployed to production and a critical vulnerability is announced in the runtime. The team cannot upgrade to .NET 6 or later immediately due to a third-party dependency. What is the best immediate action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.