Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 1Objective 1

Understanding Application Security, Threats, and Attacks CASENET Practice Questions (Page 9)

Part of the Application Security Foundations domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
4concepts

Questions 41–44

  1. 41application · medium

    A team is threat-modeling a new .NET microservice that processes payment transactions. The service communicates with an external payment gateway over HTTPS. During the session, the team identifies a threat where an attacker on the network could intercept and modify the payment request before it reaches the gateway. Which STRIDE category does this threat fall under, and which control is most appropriate?

    Select an answer first
  2. 42expert · hard

    A development team is building a .NET application that allows users to upload and share documents. The application must comply with a regulation that requires data to be encrypted at rest. The team is considering two options: (A) encrypt the files using the application's own encryption key and store the key in the web.config, or (B) use the hosting provider's managed encryption service. The security architect notes that the application must also protect against a compromised application server. Which option is more secure, and why?

    Select an answer first
  3. 43application · medium

    A team is using the DREAD model to prioritize threats for a .NET application. They have identified two threats: Threat A has a Damage of 9, Reproducibility of 8, Exploitability of 7, Affected Users of 6, and Discoverability of 5. Threat B has a Damage of 8, Reproducibility of 7, Exploitability of 6, Affected Users of 9, and Discoverability of 8. Which threat should be prioritized, and why?

    Select an answer first
  4. 44application · medium

    A .NET application has a password reset feature that sends a reset link to the user's email. An attacker discovers that the reset token is generated using `Guid.NewGuid().ToString()` and is included in the URL. Which attack is most likely to succeed, and what is the best mitigation?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CASENET

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.