
EC-CouncilCertified Application Security Engineer (.NET)
Domain 2Objective 1
Security Requirement Engineering (SRE) CASENET Practice Questions (Page 6)
Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
6concepts
Questions 26–30
- 26
In the context of the software development lifecycle, what is the primary purpose of security requirement engineering?
Select an answer first - 27
Why is traceability important in security requirements management?
Select an answer first - 28
Which technique is commonly used for security requirements validation?
Select an answer first - 29
A healthcare startup is building a .NET web application that will store patient records. During the requirements elicitation phase, the product owner states that the app must be 'secure' but provides no specifics. The compliance officer reminds the team that HIPAA applies. Which action best captures a testable security requirement from this input?
Select an answer first - 30
During a security requirements validation workshop, the team discovers that a requirement is technically infeasible with the current architecture. The requirement is to encrypt all data in a legacy database that does not support encryption. What is the best course of action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.