
EC-CouncilCertified Application Security Engineer (.NET)
Domain 8Objective 4
Web Application Firewall (WAF) CASENET Practice Questions (Page 10)
Part of the Security Testing and Secure Deployment domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
11concepts
Questions 46–50
- 46
A WAF is configured to block requests containing 'UNION SELECT' in the query string. An attacker sends: /products?id=1%20UNION%20SELECT%20username%20FROM%20users. The WAF does not block it. The application is vulnerable to SQL injection. What is the most likely reason the WAF failed?
Select an answer first - 47
A security team is comparing a WAF and a RASP solution for a .NET application. The application has a critical vulnerability that cannot be patched immediately. The team wants to block attacks against this vulnerability while the patch is developed. Which solution is more appropriate in this scenario?
Select an answer first - 48
How does a Web Application Firewall (WAF) differ from an Intrusion Detection System (IDS) in terms of its primary function?
Select an answer first - 49
A company wants to deploy a WAF in front of a public-facing ASP.NET application. The WAF should be the only entry point for HTTP traffic, and the application server should not be directly accessible from the internet. Which deployment mode should be used?
Select an answer first - 50
What is a key difference between a Web Application Firewall (WAF) and a network firewall?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CASENET
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.