Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 1Objective 1

Understanding Application Security, Threats, and Attacks CASENET Practice Questions (Page 1)

Part of the Application Security Foundations domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
4concepts

Questions 1–5

  1. 1application · medium

    A development team is using STRIDE to threat-model a new ASP.NET Core web API that exposes customer data. The API uses token-based authentication and stores sensitive data in an Azure SQL database. During the modeling session, the team identifies a threat where an attacker who obtains a valid token can access another user's data by changing an ID in the URL. Which STRIDE category does this threat belong to, and which control is most directly relevant?

    Select an answer first
  2. 2foundation · easy

    In the STRIDE threat model, what does the 'R' stand for?

    Select an answer first
  3. 3expert · hard

    A development team is adopting a DevSecOps approach for a .NET application. The team wants to integrate security testing into the CI/CD pipeline. The application is updated frequently, and the team needs to balance speed and security. Which combination of practices is most effective?

    Select an answer first
  4. 4expert · hard

    A large enterprise is developing a new customer-facing .NET web application. The security team has mandated that threat modeling be integrated into the SDLC. The development team is concerned that threat modeling will slow down the release cycle. The project manager wants to balance security with delivery speed. Which approach best addresses both concerns?

    Select an answer first
  5. 5expert · hard

    A .NET web application is deployed behind a load balancer that terminates TLS. The application uses Forms Authentication and sets a cookie named `AuthCookie`. A security review finds that the cookie is not marked `Secure`. The load balancer forwards HTTP requests to the application server. Which of the following is the most effective way to ensure the cookie is only sent over HTTPS?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.