312-95 Certified Application Security Engineer - .NET (CASE .NET) Practice Questions
Prepare for 312-95 with more than an answer.
- Exam fee
- $300 USD
- Level
- Specialist
- Valid for
- 3 years
Domains covered on the exam 10
- Understanding Application Security, Threats, and Attacks8%
- Security Requirements Gathering8%
- Secure Application Design and Architecture10%
- Secure Coding Practices for Input Validation18%
- Secure Coding Practices for Authentication and Authorization16%
- Secure Coding Practices for Cryptography12%
- Secure Coding Practices for Session Management4%
- Secure Coding Practices for Error Handling10%
- Static and Dynamic Application Security Testing (SAST & DAST)6%
- Secure Deployment and Maintenance8%
- 1
When designing a secure ASP.NET Core application, the development team implements a global authorization filter to ensure that absolutely every incoming HTTP request is checked for valid authentication and authorization claims, bypassing local caching mechanisms that might serve stale permissions. Which foundational secure design principle is being strictly applied here?
Show answer details
Correct answer: D
Complete Mediation dictates that every access to every object must be checked for authority. By implementing a global filter that checks claims on every single HTTP request and avoiding cached permissions, the team ensures no request slips through unvalidated.
flowchart TD Req[Incoming HTTP Request] --> Check{Global Auth Filter} Check -->|Valid Claims| Allow[Process Request] Check -->|Invalid/Missing| Deny[401/403 Response] - 2
A security analyst is using the DREAD model to score a newly discovered vulnerability in an internal .NET application. Which TWO of the following metrics are official components of the DREAD scoring system? (Select TWO)
Show answer details
Correct answer: D, E
DREAD stands for Damage potential, Reproducibility, Exploitability, Affected users, and Discoverability. Damage Potential assesses the extent of the harm if the vulnerability is exploited. Exploitability assesses how much effort is required to execute the attack. 'Data Sensitivity' and 'Repudiation' are not DREAD metrics (Repudiation is part of STRIDE).
DREAD stands for Damage potential, Reproducibility, Exploitability, Affected users, and Discoverability. Damage Potential assesses the extent of the harm if the vulnerability is exploited. Exploitability assesses how much effort is required to execute the attack. 'Data Sensitivity' and 'Repudiation' are not DREAD metrics (Repudiation is part of STRIDE).
- 3
An application is designed so that if the authentication database is unreachable, the system automatically denies all access requests rather than allowing a bypass or fallback to an unauthenticated state. Which secure design principle does this demonstrate?
Show answer details
Correct answer: A
Fail-safe defaults mean that the default posture of a system should be to deny access. If an error occurs (like a database crash), the system should fail securely (deny access) rather than failing open (allowing access).
- 4
A financial institution is mapping out their application security posture. The CISO wants to ensure the team understands the difference between network-level and application-level threats. Which of the following attack vectors strictly targets the application layer by exploiting insecure coding practices rather than infrastructure misconfigurations?
Show answer details
Correct answer: A
XML External Entity (XXE) injection is a direct application-layer attack that exploits poorly configured XML parsers in the application code, allowing attackers to view files on the application server filesystem or interact with backend systems. SYN Flood and BGP Hijacking are network-layer attacks, while ARP Spoofing targets the data link layer. Understanding this distinction is critical for deploying appropriate defense-in-depth strategies at the application level.
- 5
An organization is adopting the Microsoft Security Development Lifecycle (SDL) for their new ASP.NET Core project. The development team has just completed the 'Design' phase and is moving into the 'Implementation' phase. According to the Microsoft SDL, which specific security activity MUST be prioritized during this new phase?
Show answer details
Correct answer: A
In the Microsoft SDL, the Implementation phase strictly requires developers to use approved tools/compilers, deprecate unsafe functions (like older cryptographic algorithms or unmanaged unsafe code), and perform Static Application Security Testing (SAST). Threat modeling belongs to the Design phase. Dynamic analysis and fuzz testing belong to the Verification phase. Incident Response planning belongs to the Release phase.
flowchart LR A[Design] -->|Transitions to| B[Implementation] B --> C[Use Approved Tools] B --> D[Deprecate Unsafe Functions] B --> E[Static Analysis] - 6
A .NET engineering team is reviewing their legacy application against the OWASP Top 10 guidelines. They discover that the application relies heavily on
BinaryFormatterfor transmitting serialized state between microservices. Which TWO immediate security risks are introduced by this architecture? (Select TWO)Show answer details
Correct answer: A, C
BinaryFormatter is notoriously unsafe and is heavily deprecated in modern .NET because it can instantiate arbitrary types present in the application's loaded assemblies. An attacker can craft a malicious serialized payload that, when deserialized, executes arbitrary code (RCE). Additionally, it can lead to Denial of Service (DoS) by allocating massive objects or causing infinite loops during the deserialization process. It does not inherently cause SQL injection or direct DOM-based XSS.
BinaryFormatter is notoriously unsafe and is heavily deprecated in modern .NET because it can instantiate arbitrary types present in the application's loaded assemblies. An attacker can craft a malicious serialized payload that, when deserialized, executes arbitrary code (RCE). Additionally, it can lead to Denial of Service (DoS) by allocating massive objects or causing infinite loops during the deserialization process. It does not inherently cause SQL injection or direct DOM-based XSS.
