Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 1Objective 1

Understanding Application Security, Threats, and Attacks CASENET Practice Questions (Page 3)

Part of the Application Security Foundations domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
4concepts

Questions 11–15

  1. 11application · medium

    A .NET web application uses Forms Authentication and stores the authentication ticket in a cookie. During a penetration test, the tester captures the cookie and replays it from a different browser to gain access to the user's session. Which security principle was violated, and what is the most effective mitigation?

    Select an answer first
  2. 12application · medium

    A .NET application uses XML to exchange data with a partner system. An attacker sends a crafted XML document that defines an entity referencing a local file path, causing the server to include the file contents in the response. Which attack is being performed, and what is the best mitigation?

    Select an answer first
  3. 13application · medium

    A .NET application uses a `MachineKey` to protect view state and forms authentication tickets. The security team discovers that the `machineKey` is set to `AutoGenerate` in the web.config. What is the primary risk of this configuration in a web farm, and what is the best practice?

    Select an answer first
  4. 14application · medium

    A penetration tester is assessing an ASP.NET MVC application. The tester submits a search query that includes the string '<script>alert(1)</script>'. The application reflects the query in the search results page without any encoding. Which attack is the tester most likely validating, and what is the most effective mitigation?

    Select an answer first
  5. 15foundation · easy

    Which threat modeling methodology uses a data flow diagram as its central artifact and systematically identifies threats by examining how data moves through the application?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.