Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 1Objective 1

Understanding Application Security, Threats, and Attacks CASENET Practice Questions (Page 8)

Part of the Application Security Foundations domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
4concepts

Questions 36–40

  1. 36application · medium

    A security analyst is reviewing an ASP.NET application that uses a third-party component to generate PDF reports. The component has a known vulnerability that allows remote code execution. The vendor has not yet released a patch. Which action is the most appropriate immediate mitigation?

    Select an answer first
  2. 37expert · hard · select all that apply

    A security team is performing a threat model for a .NET application that allows users to upload profile pictures. The application stores the files in a directory under the web root and serves them directly. The team identifies the following threats: (1) an attacker uploads a file with a `.aspx` extension and the server executes it, (2) an attacker uploads a file with a path traversal name to overwrite a configuration file, (3) an attacker uploads a file that is too large, causing disk exhaustion. Which of the following mitigations directly address these threats? Select all that apply.

    Select an answer first
  3. 38expert · hard

    A security architect is threat-modeling a .NET application that will be accessible over the internet. The application uses a three-tier architecture: web, application, and database. The architect is considering where to place a web application firewall (WAF). Which placement provides the most comprehensive protection?

    Select an answer first
  4. 39expert · hard

    A .NET application uses a third-party REST API to fetch data. The API requires an API key. The developer hardcodes the API key in the source code. A security review flags this as a risk. Which remediation is the most secure and practical?

    Select an answer first
  5. 40expert · hard

    A .NET application is being redesigned to improve security. The current application stores session tokens in cookies without the Secure or HttpOnly flags. The new design must protect against session hijacking and XSS. The team is considering two options: Option 1 sets the Secure and HttpOnly flags on the session cookie. Option 2 uses a JavaScript-based token storage mechanism. Which option is more secure, and why?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.