
EC-CouncilCertified Application Security Engineer (.NET)
Domain 8Objective 1
Static Application Security Testing (SAST) CASENET Practice Questions (Page 7)
Part of the Security Testing and Secure Deployment domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
7concepts
Questions 31–35
- 31
A .NET team is integrating SAST into their CI/CD pipeline. They have a large legacy codebase with many existing vulnerabilities. The team wants to ensure that new code does not introduce new vulnerabilities while not being blocked by pre-existing issues. What is the most effective strategy?
Select an answer first - 32
A .NET developer is explaining SAST to a new team member. The new member asks how SAST tools can detect SQL injection without running the application. What is the most accurate explanation?
Select an answer first - 33
What does a 'false positive' mean in the context of SAST scan results?
Select an answer first - 34
In the context of SAST, what does data flow analysis primarily track?
Select an answer first - 35
A .NET developer is evaluating a SAST tool for a new project. The project uses reflection and dynamic code generation extensively. The developer is concerned that the SAST tool may not detect vulnerabilities in dynamically generated code. What is the most accurate statement about SAST limitations in this context?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.