
EC-CouncilCertified Application Security Engineer (.NET)
Domain 8Objective 4
Web Application Firewall (WAF) CASENET Practice Questions (Page 1)
Part of the Security Testing and Secure Deployment domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
11concepts
Questions 1–5
- 1
What is a key benefit of integrating WAF configuration and testing into a CI/CD pipeline?
Select an answer first - 2
A company has a WAF in front of an ASP.NET application that allows users to submit product reviews. The WAF is blocking legitimate reviews that contain the word 'select' in a sentence. The security team wants to reduce false positives without weakening protection against SQL injection. Which approach is the best?
Select an answer first - 3
Which WAF security model would you implement to allow only requests that match a predefined set of allowed HTTP methods, URL patterns, and parameter types?
Select an answer first - 4
In which WAF deployment mode does the WAF operate as a transparent proxy, requiring no changes to the client's browser configuration?
Select an answer first - 5
A security analyst notices that a WAF rule designed to block SQL injection is not catching requests like: /products?id=1%27%20OR%20%271%27%3D%271. What is the most likely reason?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.