
EC-CouncilCertified Application Security Engineer (.NET)
Domain 8Objective 1
Static Application Security Testing (SAST) CASENET Practice Questions (Page 1)
Part of the Security Testing and Secure Deployment domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
7concepts
Questions 1–5
- 1
An organization's security policy requires that all .NET applications comply with OWASP Top 10. The SAST tool is currently configured with a custom rule set that only checks for SQL injection and XSS. What should the security team do to align the SAST configuration with the policy?
Select an answer first - 2
A .NET application has a SAST finding for a potential insecure deserialization vulnerability. The code uses Json.NET with a custom SerializationBinder that restricts types to a safe allowlist. The developer believes the finding is a false positive. What is the most appropriate action?
Select an answer first - 3
What is the primary advantage of integrating SAST into a CI/CD pipeline?
Select an answer first - 4
A .NET team uses a SAST tool that generates a high number of false positives for a custom validation framework they built. The false positives are drowning out real findings. The team wants to reduce noise without losing coverage. What is the most appropriate approach?
Select an answer first - 5
A .NET solution is built using Jenkins. The security team wants to integrate SAST so that every build automatically runs the scan and publishes the results to the team. Which integration approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.