
EC-CouncilCertified Application Security Engineer (.NET)
Domain 8Objective 1
Static Application Security Testing (SAST) CASENET Practice Questions (Page 4)
Part of the Security Testing and Secure Deployment domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
7concepts
Questions 16–20
- 16
A security team is reviewing SAST results for a .NET application. The tool reports a 'Critical' finding for a command injection vulnerability in a method that executes a system command. The developer argues that the method is only called internally with hardcoded arguments and is not reachable from user input. The team has limited time to remediate. What is the most appropriate approach?
Select an answer first - 17
A SAST tool is scanning a .NET application that uses Entity Framework. The tool reports a SQL injection vulnerability in a query that uses a raw SQL string with concatenated user input. Which of the following is the most appropriate fix?
Select an answer first - 18
What is the purpose of defining a security policy in a SAST tool?
Select an answer first - 19
Which of the following vulnerabilities is a SAST tool most likely to detect in a .NET application?
Select an answer first - 20
A developer fixed a SAST finding that flagged a stored XSS vulnerability in an ASP.NET page. The fix involved encoding user input before rendering. The developer then runs the SAST scan again and the finding is gone. What is the most appropriate next step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.