
EC-CouncilCertified Application Security Engineer (.NET)
Domain 1Objective 4
Software Security Standards, Models, and Frameworks CASENET Practice Questions (Page 14)
Part of the Application Security Foundations domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 68 practice questions to prepare you well beyond it. (estimate)
68questions here
14free pages
22concepts
Questions 66–68
- 66
What is the NIST Secure Software Development Framework (SSDF) primarily designed to do?
Select an answer first - 67
A security leader is tasked with improving the software security program for a company that develops a wide range of .NET applications. The company has no formal security process, but has a mature DevOps pipeline. The leader wants to quickly establish a baseline and then drive continuous improvement. They have a limited budget and need to show progress to executives. Which combination of frameworks would be most effective?
Select an answer first - 68
An enterprise IT department wants to align its application security initiatives with overall business goals and ensure that IT governance is in place. Which framework provides guidance for governance and management of enterprise IT, including application security?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CASENET
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.