
EC-CouncilCertified Application Security Engineer (.NET)
Domain 8Objective 4
Web Application Firewall (WAF) CASENET Practice Questions (Page 3)
Part of the Security Testing and Secure Deployment domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
11concepts
Questions 11–15
- 11
A WAF administrator needs to configure a rule that only allows requests to /api/orders with a valid API key in the 'X-API-Key' header. All other requests should be blocked. Which WAF rule configuration best achieves this?
Select an answer first - 12
After deploying a WAF with default rules, legitimate users are being blocked when they submit a form that includes a text field containing the word 'select' in a sentence. The WAF logs show the requests are being blocked by a SQL injection rule. What is the best action to reduce false positives while maintaining security?
Select an answer first - 13
Which WAF tuning approach would reduce false positives while maintaining security coverage?
Select an answer first - 14
What is a common cause of false positives in a WAF?
Select an answer first - 15
A WAF administrator is configuring a rule to block HTTP parameter pollution (HPP) attacks. The application uses the first value of a duplicated parameter. An attacker sends: /api/transfer?amount=100&amount=10000. Which WAF rule best mitigates this attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.