Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (.NET)

Domain 6Objective 3

ViewState-based Session Management CASENET Practice Questions (Page 5)

Part of the Secure Coding: Session Management domain, which makes up ~10% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
5concepts

Questions 21–25

  1. 21application · medium

    An ASP.NET application is being hardened. The security team wants to ensure that ViewState cannot be tampered with and that its contents are not readable by the client. The application does not use ViewState for any sensitive data, but the team wants defense-in-depth. What configuration should be applied?

    Select an answer first
  2. 22application · medium

    A developer is reviewing an ASP.NET page that uses ViewState to store a user's account number for display after postback. The application does not require ViewState for any other purpose. The security policy states that sensitive data should not be exposed to the client. What is the best practice?

    Select an answer first
  3. 23application · easy

    A security scan flags that an ASP.NET application's ViewState is not protected against tampering. The application is deployed on a single server and uses the default machineKey configuration. Which action should the developer take to mitigate the risk?

    Select an answer first
  4. 24expert · medium

    An ASP.NET application is deployed on a single server. The developer wants to ensure that ViewState is protected against both tampering and disclosure. The application currently has ViewState MAC validation enabled but encryption is disabled. What is the minimum change required?

    Select an answer first
  5. 25application · medium

    A security audit reveals that an ASP.NET application's ViewState is not protected against tampering. The application runs on a single server and uses ViewState for a non-sensitive UI state. The developer needs to implement a quick fix to ensure ViewState integrity. What should the developer do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.