EC-Council · CASE-.NET
Validates the ability to build secure .NET applications throughout the software development lifecycle, covering secure requirements gathering, input validation, authentication and authorization, cryptographic practices, error handling, session management, and security testing.
Practice Questions
625
≈ 5 practice exams
Duration
120 minutes
Passing Score
70%
Difficulty
AssociateLast Updated
Sep 2026
EC-Council structures the CASE .NET exam (code 312-95) around 10 course modules but does not publish per-module weights, so treat all 10 as fair game: application security threats and attacks, security requirements gathering, secure application design and architecture, then five secure-coding modules (input validation, authentication and authorization, cryptography, session management, error handling), followed by static and dynamic application security testing (SAST and DAST) and secure deployment and maintenance. The five secure-coding modules are where .NET-specific detail concentrates, things like ASP.NET validation controls, System.Security.Cryptography usage, and session token handling, and this 625-question bank is built to give each of the 10 modules real depth rather than skimming the coding chapters.
Test day is short and dense: 50 multiple-choice questions in 120 minutes, delivered through the EC-Council Exam Portal with remote proctoring by EC-Council's RPS team. The published passing score is 70%, which works out to 35 correct out of 50. EC-Council does not disclose any scored versus unscored split for this exam, so assume every question counts. With less than 2.5 minutes per question and scenario stems that quote actual .NET code, unprepared candidates tend to lose time parsing C# snippets rather than recalling concepts.
Eligibility is formal, not just recommended: you must either complete official EC-Council CASE training (ATC, iWeek, or iLearn), be an ECSP .NET or Java member in good standing, have a minimum of 2 years of working experience in the InfoSec or software domain, or hold an equivalent certification such as GSSP .NET or Java. The experience and equivalent-cert routes require a non-refundable USD 100 eligibility application fee, and the exam voucher itself is USD 450 through the EC-Council store. The certification is valid for 3 years and renews under the ECE program (120 credits per 3-year cycle plus the USD 80 annual membership fee). Start with the 30 free questions, then work through the full 625-question bank until your accuracy holds steady across all 10 modules.
The Certified Application Security Engineer .NET (CASE .NET) is an application security certification offered by EC-Council that validates a software developer's ability to integrate security practices throughout every phase of the .NET software development lifecycle (SDLC). Developed in partnership with global application and software development experts, it tests critical security knowledge and skills spanning pre-deployment through post-deployment phases, with a focus on .NET-specific secure coding techniques including input validation, authentication and authorization mechanisms, cryptographic implementation, session management, and error handling.
The certification covers the full spectrum of SDLC security activities: from gathering secure requirements and designing secure architectures, to writing defensively coded .NET applications and performing security testing using both static (SAST) and dynamic (DAST) analysis methods. It addresses real-world threats and attack vectors targeting .NET web applications and teaches developers to build security in from the ground up rather than bolt it on after deployment. The exam is identified by exam code 312-95 and is recognized globally as a benchmark for application security competency in the Microsoft .NET ecosystem.
CASE .NET is designed primarily for .NET developers with a minimum of two years of professional development or information security experience who want to formalize their application security expertise. It is equally relevant for application security engineers, security analysts, and security testers who work with .NET-based systems and need to demonstrate proficiency in secure SDLC practices.
The certification is also well-suited for software architects, DevSecOps practitioners, and anyone involved in designing, building, testing, managing, or protecting .NET applications — including web applications, mobile applications, and IoT solutions built on the .NET framework. Professionals transitioning from pure development roles into application security roles will find this certification particularly valuable for validating their security-oriented coding skills.
There are no strict formal educational prerequisites, but EC-Council requires candidates to meet at least one of the following eligibility criteria before sitting for the exam: complete official EC-Council CASE training through an accredited training partner (ATC, iWeek, or iClass), be an active EC-Council Secure Programmer (ECSP) .NET or Java member in good standing, possess a minimum of two years of working experience in the information security or software development domain, or hold an equivalent industry certification such as GIAC GSSP-.NET or GSSP-Java. Candidates applying via the experience or equivalent-certification pathway must submit a USD $100 non-refundable application fee.
In terms of recommended knowledge, candidates should have hands-on familiarity with the .NET framework and C# or VB.NET development, a working understanding of web application architectures, and foundational knowledge of common vulnerability categories such as those defined by OWASP. Familiarity with basic cryptographic concepts, HTTP/HTTPS protocols, and software testing methodologies will also ease preparation for the exam domains.
The CASE .NET exam (312-95) consists of 50 multiple-choice questions and must be completed within 120 minutes. The passing score is 70%, meaning candidates must answer at least 35 questions correctly. The exam is delivered through the EC-Council exam portal and can be taken at authorized Prometric testing centers or, in eligible cases, via online proctored delivery.
All 50 questions are scored; no unscored or survey items have been publicly disclosed. The multiple-choice format tests both conceptual understanding and practical application of secure coding principles across the ten defined exam domains. Candidates who do not pass may retake the exam, subject to EC-Council's standard retake policies.
Earning the CASE .NET certification positions professionals for roles such as Application Security Engineer, Secure Software Developer, Security Analyst, DevSecOps Engineer, and Application Security Tester — all of which are in strong demand as organizations increasingly require security expertise embedded within development teams rather than solely in separate security departments. The credential is recognized globally and is valued by employers across financial services, healthcare, government, and technology sectors where .NET remains a dominant development platform.
The CASE .NET complements other EC-Council certifications such as the CEH and CPENT by providing a developer-focused security credential, and it stacks well with Microsoft-specific certifications for professionals building careers in the Microsoft ecosystem. Certified professionals typically see enhanced earning potential relative to non-certified peers, and the credential supports long-term career growth by demonstrating a structured, SDLC-wide approach to application security that aligns with frameworks such as OWASP SAMM and NIST SSDF.
5 sample questions with answers and explanations. The full bank has 625 questions, enough for 5 full-length practice exams.
Preview — answers shown1. A security code review identifies use of BinaryFormatter for deserializing user-uploaded files. What is the critical security risk? (Select one!)
Explanation
BinaryFormatter is vulnerable to deserialization attacks that can execute arbitrary code. Attackers can craft malicious serialized payloads that instantiate dangerous types and execute code during deserialization. Microsoft has marked BinaryFormatter as obsolete and dangerous. The vulnerability exists because BinaryFormatter honors type information in the serialized stream and can instantiate any type available to the application. Safe alternatives include JsonSerializer for data transfer objects or DataContractSerializer with known types. While performance and data issues may exist, the critical security risk is remote code execution which allows complete system compromise.
2. A DREAD risk assessment evaluates a discovered SQL injection vulnerability. The ratings are: Damage=9, Reproducibility=10, Exploitability=8, Affected Users=10, Discoverability=7. What is the overall DREAD risk score? (Select one!)
Explanation
DREAD calculates overall risk by averaging the five factor scores: (9 + 10 + 8 + 10 + 7) / 5 = 8.8. Each factor rates from 1-10 based on severity. Damage assesses harm from successful exploit. Reproducibility measures how consistently the attack works. Exploitability evaluates skill and resources required. Affected Users quantifies impact scope. Discoverability rates ease of finding the vulnerability. The average provides a 1-10 risk score for prioritizing remediation. This SQL injection scores 8.8 indicating high risk requiring immediate attention. DREAD complements STRIDE by quantifying threat severity for risk-based decision making.
3. A .NET application uses ECDsa for digital signatures with elliptic curve cryptography. Which key size provides security equivalent to RSA 3072-bit encryption? (Select one!)
Explanation
A 256-bit ECDSA key provides security equivalent to approximately 3072-bit RSA encryption. Elliptic curve cryptography achieves the same security level with much smaller key sizes compared to RSA. The security equivalence is approximately: 256-bit ECC equals 3072-bit RSA, 384-bit ECC equals 7680-bit RSA, and 521-bit ECC provides even higher security equivalent to 15360-bit RSA. This is why ECDSA and other elliptic curve algorithms are preferred for mobile and IoT devices where smaller signatures and faster operations are beneficial. The smaller key sizes result in faster cryptographic operations, smaller signatures, and reduced bandwidth requirements while maintaining equivalent security strength. ECDSA keys do not typically exceed 521 bits, making 1024-bit ECDSA keys non-standard.
4. A software development team applies the Microsoft Security Development Lifecycle (SDL) to their project. During which SDL phase should threat modeling using STRIDE be performed? (Select one!)
Explanation
Threat modeling using STRIDE should be performed during the Design Phase of the SDL. This allows security threats to be identified and mitigated before implementation begins, reducing the cost and complexity of security fixes. The Implementation Phase focuses on secure coding practices and using approved tools. The Verification Phase involves security testing and validation. The Response Phase handles incident response planning and security updates after release.
5. A security audit evaluates XML parsing implementations. Which XmlReaderSettings configuration prevents XXE attacks? (Select two!)
Multiple correct answersExplanation
DtdProcessing.Prohibit disables DTD processing entirely, preventing DTD-based XXE attacks. Setting XmlResolver to null prevents the parser from resolving external entities referenced in the XML. Both settings are required for complete XXE protection. DtdProcessing.Parse enables DTD processing which allows XXE. XmlUrlResolver actively resolves external entities enabling XXE attacks. MaxCharactersFromEntities should be set to a reasonable limit like 1000, not int.MaxValue which allows entity expansion attacks. In .NET Core and .NET 5+, these secure defaults are set automatically, but explicit configuration ensures protection in all framework versions.
50 multiple-choice questions in 120 minutes, delivered through the EC-Council Exam Portal with remote proctoring by EC-Council's RPS team.
EC-Council publishes a 70% passing score for CASE .NET, which means 35 correct answers out of 50. Unlike some EC-Council exams (such as CEH) that use variable per-form cut scores, the CASE .NET page states a flat 70%.
The exam voucher is USD 450 through the official EC-Council store, and candidates qualifying via the experience or equivalent-certification route also pay a non-refundable USD 100 eligibility application fee. Official training packages price separately and typically include the exam.
One of four routes: official EC-Council CASE training (ATC, iWeek, or iLearn), active ECSP .NET or Java membership in good standing, a minimum of 2 years of working experience in the InfoSec or software domain, or an equivalent certification such as GSSP .NET or Java. The last two routes require the USD 100 application fee.
Ten modules: application security threats and attacks, security requirements gathering, secure design and architecture, secure coding for input validation, authentication and authorization, cryptography, session management, error handling, SAST and DAST testing, and secure deployment and maintenance. EC-Council does not publish per-module weights.
All 50 questions are multiple choice. Many stems are scenario-based and reference .NET-specific code and APIs, so expect to read C# and ASP.NET snippets under time pressure rather than answer pure definition questions.
It is valid for 3 years. CASE falls under EC-Council's ECE scheme, so renewal requires 120 ECE credits per 3-year cycle plus the USD 80 annual EC-Council membership fee.
EC-Council Certified DevSecOps Engineer (ECDE) v2
ECDE · 609 questions
Digital Forensics Essentials (DFE)
DFE · 626 questions
EC-Council Certified Disaster Recovery Professional (EDRP)
EDRP · 623 questions
EC-Council Certified Incident Handler (ECIH)
ECIH · 590 questions
EC-Council Certified Encryption Specialist (ECES)
ECES · 627 questions
Ethical Hacking Essentials (EHE)
EHE · 627 questions
$17.99
One-time access to this exam