
EC-CouncilCertified Application Security Engineer (.NET)
Domain 1Objective 3
Why Applications Become Vulnerable to Attacks CASENET Practice Questions (Page 10)
Part of the Application Security Foundations domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
7concepts
Questions 46–50
- 46
A company has a policy that requires all employees to change their passwords every 30 days. The policy is enforced, but employees often write their passwords on sticky notes. The security team wants to improve password security without causing too much friction. What is the best approach?
Select an answer first - 47
A startup wants to maximize user adoption of its new file-sharing app. To reduce friction, the product manager insists on allowing users to share files via unauthenticated links that never expire. The security team warns this could expose sensitive data. What is the most balanced approach that still maintains usability?
Select an answer first - 48
Which scenario is an example of an external attacker exploiting an application weakness?
Select an answer first - 49
A team is building a new feature that allows users to upload profile pictures. The feature will accept multiple image formats and store them on a public CDN. The team wants to minimize the attack surface. Which design decision is most effective?
Select an answer first - 50
During a post-incident review, a team discovers that a SQL injection vulnerability was introduced because the developer concatenated user input directly into a query. The vulnerability was not caught during testing because the test cases only used valid input. At which lifecycle stage was the vulnerability most likely to have been introduced, and which stage failed to catch it?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CASENET
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.