ExamDumpster

Free 312-95 sample questions

Real questions from the Certified Application Security Engineer - .NET (CASE .NET) practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 6 of 12 free sample questions.

Question 1Choose one

A financial institution is mapping out their application security posture. The CISO wants to ensure the team understands the difference between network-level and application-level threats. Which of the following attack vectors strictly targets the application layer by exploiting insecure coding practices rather than infrastructure misconfigurations?

Question 2Choose one

An organization is adopting the Microsoft Security Development Lifecycle (SDL) for their new ASP.NET Core project. The development team has just completed the 'Design' phase and is moving into the 'Implementation' phase. According to the Microsoft SDL, which specific security activity MUST be prioritized during this new phase?

Question 3Choose 2

A .NET engineering team is reviewing their legacy application against the OWASP Top 10 guidelines. They discover that the application relies heavily on `BinaryFormatter` for transmitting serialized state between microservices. Which TWO immediate security risks are introduced by this architecture? (Select TWO)

Question 4Choose one

True or False: In a secure Software Development Life Cycle (SDLC), defining Role-Based Access Control (RBAC) matrices and specifying encryption algorithms for data at rest are considered functional activities rather than security activities.

Question 5Choose one

A development team is using the SQUARE (Security Quality Requirements Engineering) model to identify and prioritize security requirements for a new financial portal. They have just completed 'Step 3: Develop artifacts' which included creating architecture diagrams and use cases. What is the immediate next step in the SQUARE methodology?

Question 6Choose one

A large healthcare provider is initiating a major overhaul of their patient management system. The organization handles highly sensitive Protected Health Information (PHI) and relies on a mix of legacy on-premises servers and modern cloud infrastructure. The Chief Information Security Officer (CISO) mandates a robust, organizational-wide risk assessment before any code is written. The chosen methodology must be self-directed, focus heavily on organizational risks rather than just technological flaws, and specifically build asset-based threat profiles as its primary foundation. The security engineering team is evaluating different requirement and risk models. They need a framework that progresses through organizational views, technological views, and finally strategy development. Which of the following models is the MOST appropriate for this specific scenario?

6 more free samples are waiting

Create a free account to unlock the whole 312-95 sample bank, or get full access to all 138 practice questions in the simulator.

Create account