
EC-CouncilCertified Application Security Engineer (.NET)
Domain 5Objective 1
Symmetric Encryption and Defensive Coding CASENET Practice Questions (Page 7)
Part of the Secure Coding: Cryptography domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
5concepts
Questions 31–35
- 31
A developer is implementing AES-GCM in a .NET application. The code currently uses a static 12-byte nonce that is the same for every encryption operation. What is the most critical security issue with this implementation?
Select an answer first - 32
A .NET application uses AES-256 to encrypt data and stores the key in a .config file. The security team requires that the key be protected from being read by other applications running on the same server. Which approach should be used?
Select an answer first - 33
A developer is implementing AES-CBC encryption and needs to handle data that is not a multiple of the block size. Which approach is correct?
Select an answer first - 34
Which of the following is a symmetric encryption algorithm?
Select an answer first - 35
Which of the following is a secure coding practice for symmetric encryption?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.