
EC-CouncilCertified Application Security Engineer (.NET)
Domain 1Objective 1
Understanding Application Security, Threats, and Attacks CASENET Practice Questions (Page 2)
Part of the Application Security Foundations domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
4concepts
Questions 6–10
- 6
A .NET application uses a SQL query built by concatenating a user-supplied `categoryId` string directly into a `SELECT` statement. An attacker submits `1 OR 1=1` and retrieves all records. The team decides to fix the issue. Which change is the most appropriate?
Select an answer first - 7
A .NET application has a file upload feature that accepts PDF files. The application checks the file extension and content type header, but a tester successfully uploads a file with a .pdf extension that contains an ASPX script. The file is stored in a directory that is served by IIS. Which additional control is most effective in preventing this attack?
Select an answer first - 8
A .NET developer is writing a method that logs user actions. The method accepts a username and an action description. The log entries are stored in a text file and later displayed in an internal admin portal. Which implementation best follows secure coding practices?
Select an answer first - 9
In application design, what is the purpose of implementing input validation on both the client side and the server side?
Select an answer first - 10
Which security principle ensures that a user or process is granted only the minimum privileges necessary to perform its required functions?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.