Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 1Objective 1

Understanding Application Security, Threats, and Attacks CASENET Practice Questions (Page 7)

Part of the Application Security Foundations domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
4concepts

Questions 31–35

  1. 31expert · hard

    A .NET application has an admin panel that is accessible over the internet. The security team wants to reduce the risk of brute-force attacks on the admin login. The application uses ASP.NET Identity. Which combination of measures is most effective?

    Select an answer first
  2. 32application · medium

    A team is threat-modeling an ASP.NET application that allows users to upload profile pictures. They draw a data flow diagram and identify an external entity (the user) sending data to a process (the upload handler) that stores files in a database. Which threat is most directly associated with the data flow between the user and the upload handler?

    Select an answer first
  3. 33foundation · easy

    Which attack technique involves an attacker inserting malicious SQL statements into an application's input fields to manipulate database queries?

    Select an answer first
  4. 34application · medium

    A security architect is using the STRIDE methodology to analyze a new ASP.NET Core application. They identify a threat where an attacker can modify the `role` claim in a JWT token to gain admin privileges. Which STRIDE category does this threat fall under, and what is the most effective mitigation?

    Select an answer first
  5. 35application · medium

    A team is using the STRIDE methodology to analyze a .NET application that allows users to transfer money between accounts. They identify a threat where an attacker can intercept the transfer request and change the destination account number. Which STRIDE category does this threat belong to, and what is the best mitigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.