
EC-CouncilCertified Application Security Engineer (.NET)
Domain 2Objective 5
Threat Modeling CASENET Practice Questions (Page 10)
Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 46–50
- 46
Which stakeholders should be involved in the threat modeling process to ensure security requirements are addressed?
Select an answer first - 47
A security team wants to adopt a threat modeling tool for their .NET projects. They need the tool to integrate with Azure DevOps and automatically generate DFDs from the code. Which tool capability is most important to evaluate?
Select an answer first - 48
In the threat modeling process, what is the role of identifying trust boundaries?
Select an answer first - 49
Which STRIDE category is primarily concerned with an attacker gaining higher privileges than they are authorized to have?
Select an answer first - 50
A development team is adopting threat modeling for the first time. They want to integrate it into their existing Agile sprints without slowing down delivery. The team has a small security budget and limited security expertise. Which approach best balances security value with development velocity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.