
EC-CouncilCertified Application Security Engineer (.NET)
Domain 2Objective 3
Security Quality Requirements Engineering (SQUARE) CASENET Practice Questions (Page 2)
Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
7concepts
Questions 6–10
- 6
A .NET development team is starting a new project for a healthcare portal. The security lead wants to use SQUARE to ensure security requirements are captured early. The team has limited time and budget. Which SQUARE step should the team perform FIRST to ensure the subsequent requirements elicitation is focused on the most critical assets?
Select an answer first - 7
A development team is adopting SQUARE for a new .NET microservices project. They want to ensure security requirements are addressed early and not retrofitted. At which point in the SDLC should the SQUARE process be integrated?
Select an answer first - 8
A company is considering whether to adopt SQUARE for a small, internal .NET tool with limited security exposure. The team is concerned about the overhead of the full SQUARE process. What is the most appropriate recommendation?
Select an answer first - 9
A .NET team has identified a set of security requirements for a new application. The risk assessment shows that the highest-risk requirement is also the most expensive to implement. The project has a fixed budget and a tight deadline. The stakeholders are divided: some want to include the expensive requirement, others want to defer it to a later release. What is the BEST decision for the team?
Select an answer first - 10
A team has completed SQUARE for a .NET application and produced a prioritized list of security requirements. During implementation, a new critical vulnerability is discovered in a third-party library used by the application. The team must decide whether to add a new requirement to address this vulnerability, potentially displacing a previously prioritized requirement. What should they do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.