
EC-CouncilCertified Application Security Engineer (.NET)
Domain 8Objective 1
Static Application Security Testing (SAST) CASENET Practice Questions (Page 9)
Part of the Security Testing and Secure Deployment domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
7concepts
Questions 41–45
- 41
How do SAST tools analyze source code to detect vulnerabilities?
Select an answer first - 42
A security team is triaging SAST findings for a .NET application. The tool reports a 'High' severity finding for an insecure deserialization vulnerability in a method that deserializes data from a cookie. The team is unsure whether the finding is a true positive because the cookie data is encrypted. What is the most appropriate action?
Select an answer first - 43
A .NET development team uses a SAST tool that supports custom rules. They want to enforce a company-specific rule that disallows the use of the 'DES' cryptographic algorithm. What is the most appropriate way to implement this requirement?
Select an answer first - 44
A SAST report flags a 'Critical' finding for a command injection vulnerability in a .NET application. The code uses Process.Start with a string that includes user input. The team lead wants to confirm the finding before remediation. What is the most appropriate action?
Select an answer first - 45
Why is it important to customize SAST rulesets to match your organization's technology stack and security requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CASENET
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.