
EC-CouncilCertified Application Security Engineer (.NET)
Domain 1Objective 3
Why Applications Become Vulnerable to Attacks CASENET Practice Questions (Page 9)
Part of the Application Security Foundations domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
7concepts
Questions 41–45
- 41
A bank's application was breached. The investigation shows that the attacker used a valid employee account to access customer records. The employee had recently been terminated but their account was not disabled. Which type of threat source does this represent?
Select an answer first - 42
Which human factor is most likely to lead to an application vulnerability?
Select an answer first - 43
A development team is under pressure to deliver a new customer portal quickly. To save time, they skip the security code review and deploy the application with default credentials for the admin account. A week later, an attacker logs in with the default credentials and steals customer data. Which combination of factors most directly contributed to this vulnerability?
Select an answer first - 44
A developer at a software company is writing code for a new .NET web service. The developer has not received any security training and is unaware of common vulnerabilities. Which outcome is most likely to occur?
Select an answer first - 45
Which scenario best illustrates a security misconfiguration that could make an application vulnerable?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASENET” is a trademark of its owner, used for identification only.