Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 5Objective 1

Symmetric Encryption and Defensive Coding CASENET Practice Questions (Page 8)

Part of the Secure Coding: Cryptography domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
5concepts

Questions 36–38

  1. 36expert · medium

    A developer is encrypting a large file (several GB) using AES-GCM in .NET. The current implementation loads the entire file into memory and encrypts it in one call. The application is running on a server with limited memory. What is the best approach?

    Select an answer first
  2. 37expert · medium

    A company needs to encrypt data in a multi-tenant SaaS application. Each tenant's data must be encrypted with a unique key, and the keys must be managed separately. The application is built on .NET and uses Azure. Which approach provides the best isolation and manageability?

    Select an answer first
  3. 38application · medium

    An organization is required to rotate encryption keys every 90 days. The current .NET application uses a single symmetric key stored in a configuration file to encrypt data at rest. The team wants to minimize downtime and avoid re-encrypting all existing data during rotation. What is the most appropriate approach?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CASENET

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.