Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 8Objective 1

Static Application Security Testing (SAST) CASENET Practice Questions (Page 6)

Part of the Security Testing and Secure Deployment domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
7concepts

Questions 26–30

  1. 26foundation · easy

    What is a potential risk when remediating a SAST finding by adding input validation?

    Select an answer first
  2. 27application · medium

    A .NET team wants to add SAST to their CI pipeline, but they are concerned about slowing down the build. The codebase is large, and a full scan takes over an hour. Which approach best addresses this concern while maintaining security coverage?

    Select an answer first
  3. 28application · medium

    A .NET team uses GitHub Actions for CI. They want to run SAST on every push to any branch, but they are concerned about the cost of running scans on every push. What is the most cost-effective approach that still provides security coverage?

    Select an answer first
  4. 29expert · hard

    A .NET team is integrating SAST into their CI pipeline. They have a large monorepo with multiple solutions. The security team wants to enforce a policy that no new High or Critical vulnerabilities are introduced, but they also want to avoid blocking the pipeline on legacy issues. The team is considering using a baseline. What is the most appropriate way to implement this?

    Select an answer first
  5. 30application · medium

    A .NET team has just integrated a SAST tool into their CI pipeline. The tool currently fails the build on any 'High' or 'Critical' finding, but developers complain that many of these findings are in legacy code that is not part of the current sprint. The security lead wants to keep the pipeline fast and avoid blocking unrelated work. What is the most appropriate configuration?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.