
EC-CouncilCertified Application Security Engineer (.NET)
Domain 8Objective 5
Security Maintenance and Monitoring CASENET Practice Questions (Page 6)
Part of the Security Testing and Secure Deployment domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
6concepts
Questions 26–30
- 26
What is the first step in an effective security incident response procedure?
Select an answer first - 27
A .NET application is suspected of being breached. The security team has limited staff and must decide whether to contain the incident by taking the server offline or keep it online to gather more forensic evidence. The application is business-critical, and downtime is costly. The compliance team requires that the incident be reported to regulators within 72 hours. What is the most appropriate decision?
Select an answer first - 28
A .NET application processes credit card data and is subject to PCI DSS. The security team is implementing a security maintenance plan and must ensure that all maintenance activities are logged and that the logs are reviewed regularly. The team has a limited budget and cannot afford a dedicated log management solution. What is the most effective way to meet the PCI DSS logging and review requirement?
Select an answer first - 29
A .NET e-commerce application runs on IIS with SQL Server. The security team wants to detect credential-stuffing attempts and account lockouts in near real time. They need a solution that captures both successful and failed logins, correlates them with the user account, and triggers an alert when multiple failures occur within a short window. What should the team configure?
Select an answer first - 30
A financial services company runs a .NET Framework 4.8 web application on Windows Server 2019. The security team has identified a critical vulnerability in a third-party NuGet package used for PDF generation. The vendor has released a patched version, but the application also uses a custom library that depends on the vulnerable version. The change advisory board requires a rollback plan and a test window before production deployment. What is the most appropriate first step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.