
EC-CouncilCertified Application Security Engineer (.NET)
Domain 8Objective 4
Web Application Firewall (WAF) CASENET Practice Questions (Page 8)
Part of the Security Testing and Secure Deployment domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
11concepts
Questions 36–40
- 36
In a CI/CD pipeline, which of the following is an appropriate step to test WAF rules?
Select an answer first - 37
A WAF administrator is reviewing logs and sees a pattern of requests with a 'Content-Type' header of 'application/x-www-form-urlencoded' but with a body that contains JSON. The requests are being blocked by a rule that inspects JSON payloads. What is the most likely cause, and what should the administrator do?
Select an answer first - 38
A security architect is designing a defense-in-depth strategy for an ASP.NET application. The team already has a WAF and a network IDS. They want to add a control that can detect and block attacks that the WAF misses, especially those that exploit application logic flaws. Which control should they add?
Select an answer first - 39
Which of the following attack patterns would a WAF rule designed to mitigate SQL injection typically look for?
Select an answer first - 40
A WAF administrator needs to block requests that attempt to include a file from a remote server, such as http://evil.com/shell.txt, in a parameter. Which WAF rule is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.