Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 2Objective 5

Threat Modeling CASENET Practice Questions (Page 4)

Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
10concepts

Questions 16–20

  1. 16foundation · easy

    What is the primary purpose of threat modeling in the secure software development lifecycle?

    Select an answer first
  2. 17application · medium

    A security lead is choosing a threat modeling methodology for a new .NET microservices application. The team needs to systematically categorize threats by their nature (e.g., spoofing, tampering) and also assign a numeric risk score to prioritize fixes. Which combination of methodologies best meets both needs?

    Select an answer first
  3. 18application · medium

    During threat modeling of an ASP.NET Core API, the team identifies two threats: (1) an unauthenticated attacker can brute-force the login endpoint, and (2) a low-privileged user can access another user's data by manipulating an ID in the URL. Using DREAD for prioritization, which threat should be addressed first?

    Select an answer first
  4. 19foundation · easy

    In the STRIDE model, which threat category involves an attacker pretending to be another user or system?

    Select an answer first
  5. 20application · medium

    A development team is new to threat modeling and asks when it should be performed in the SDLC. Which guidance is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.