Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 2Objective 5

Threat Modeling CASENET Practice Questions (Page 7)

Part of the Security Requirements and Secure Design domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 2–2 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
10concepts

Questions 31–35

  1. 31application · medium

    A threat modeling team is using STRIDE to analyze a .NET application that uses a third-party payment gateway. They want to identify threats related to the integration. Which technique is most effective?

    Select an answer first
  2. 32foundation · easy

    Which threat modeling methodology uses a tree structure to represent an attacker's goals and the various ways to achieve them?

    Select an answer first
  3. 33foundation · easy

    Why is it important to prioritize threats in threat modeling?

    Select an answer first
  4. 34application · medium

    A .NET application exposes an API endpoint that returns user profile data. During threat modeling, the team identifies that an attacker could enumerate other users' profiles by changing the user ID in the request. Which STRIDE category does this threat represent, and what is the best mitigation?

    Select an answer first
  5. 35foundation · easy

    When prioritizing threats, which two factors are most commonly used to assess risk?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.