
EC-CouncilCertified Application Security Engineer (.NET)
Domain 8Objective 5
Security Maintenance and Monitoring CASENET Practice Questions (Page 2)
Part of the Security Testing and Secure Deployment domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
6concepts
Questions 6–10
- 6
During a security incident, the incident response team needs to determine whether an attacker exfiltrated data from a .NET application's database. Which evidence source is most useful?
Select an answer first - 7
A .NET application was breached. The incident response team is developing a post-incident action plan. Which actions are appropriate to include? Select all that apply.
Select an answer first - 8
What is a key benefit of maintaining audit logs of security maintenance activities?
Select an answer first - 9
What is the primary reason to apply security patches to the .NET framework and third-party libraries in a deployed application?
Select an answer first - 10
A .NET application is hosted in a hybrid cloud environment. The security team needs to implement centralized logging and monitoring that captures security-relevant events from both on-premises and cloud components. The compliance team requires that logs be retained for 1 year and that access to logs be audited. The budget is limited, so the team cannot use a commercial SIEM. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.