
EC-CouncilCertified Application Security Engineer (.NET)
Domain 2Objective 5
Threat Modeling CASENET Practice Questions (Page 4)
Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 16–20
- 16
What is the primary purpose of threat modeling in the secure software development lifecycle?
Select an answer first - 17
A security lead is choosing a threat modeling methodology for a new .NET microservices application. The team needs to systematically categorize threats by their nature (e.g., spoofing, tampering) and also assign a numeric risk score to prioritize fixes. Which combination of methodologies best meets both needs?
Select an answer first - 18
During threat modeling of an ASP.NET Core API, the team identifies two threats: (1) an unauthenticated attacker can brute-force the login endpoint, and (2) a low-privileged user can access another user's data by manipulating an ID in the URL. Using DREAD for prioritization, which threat should be addressed first?
Select an answer first - 19
In the STRIDE model, which threat category involves an attacker pretending to be another user or system?
Select an answer first - 20
A development team is new to threat modeling and asks when it should be performed in the SDLC. Which guidance is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.