
EC-CouncilCertified Application Security Engineer (.NET)
Domain 1Objective 3
Why Applications Become Vulnerable to Attacks CASENET Practice Questions (Page 6)
Part of the Application Security Foundations domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
7concepts
Questions 26–30
- 26
A .NET web application currently requires users to enter a complex password and a one-time code sent via SMS for every login. User feedback indicates this process is too cumbersome, and the product owner wants to reduce friction. Which change best balances security and functionality?
Select an answer first - 27
A company has a .NET web application that is accessible both internally and externally. The security team is conducting a risk assessment and needs to prioritize threats. Which threat should be considered the highest risk?
Select an answer first - 28
What is the primary purpose of threat modeling in application security?
Select an answer first - 29
A company's web application uses an open-source library for image processing. The library has a known critical vulnerability, but the team has not updated it because the update changes the API and would require significant code changes. An attacker exploits the vulnerability to execute arbitrary code. What is the most effective way to prevent this class of vulnerability in the future?
Select an answer first - 30
What is the best practice for managing third-party components to reduce security risks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.