
EC-CouncilCertified Application Security Engineer (.NET)
Domain 8Objective 4
Web Application Firewall (WAF) CASENET Practice Questions (Page 9)
Part of the Security Testing and Secure Deployment domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
11concepts
Questions 41–45
- 41
What is a common high-availability configuration for a WAF to ensure uninterrupted service?
Select an answer first - 42
A company is deploying a WAF in front of a high-traffic ASP.NET application. The WAF must handle peak traffic without introducing significant latency. Which configuration is the best to achieve both high availability and low latency?
Select an answer first - 43
A WAF rule is configured to block requests where the User-Agent header contains 'curl'. What HTTP attribute is this rule inspecting?
Select an answer first - 44
A WAF log shows a series of requests to /search.aspx with the parameter 'q' containing values like '%27%20OR%20%271%27%3D%271'. The requests come from a single IP address and are spaced 5 seconds apart. The WAF has a rule that blocks requests containing 'OR 1=1' after URL decoding. The requests are not being blocked. What is the most likely reason?
Select an answer first - 45
An attacker is trying to bypass a WAF by sending a request with the payload: /search?q=%u0027%20OR%201%3D1--. The WAF does not decode Unicode escapes. Which bypass technique is being used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.