312-95 Sample Questions

312-95 Sample Questions & Answers

Defensive coding against injection through input validation takes the largest slice, alongside security fundamentals, requirements and threat modeling, authentication and authorization, .NET cryptography, session handling, error handling, and SAST/DAST testing.

Launch the full 312-95 simulator →

Showing 6 of 12 free samples.

  1. Question 1Beginner

    Understanding Application Security, Threats, and Attacks · SDLC Security Integration

    True or False: In a secure Software Development Life Cycle (SDLC), defining Role-Based Access Control (RBAC) matrices and specifying encryption algorithms for data at rest are considered functional activities rather than security activities.

    Show answer & explanation

    Correct answer: B

    False. Defining RBAC matrices and specifying encryption algorithms are explicitly security activities (or security requirements). Functional activities describe what the system should do for the user (e.g., 'The system must allow a user to add items to a cart'), whereas security activities dictate how the system must protect itself and its data (e.g., 'The system must encrypt cart data using AES-256').

  2. Question 2Intermediate

    Security Requirements Gathering · Security Requirements Models

    A development team is using the SQUARE (Security Quality Requirements Engineering) model to identify and prioritize security requirements for a new financial portal. They have just completed 'Step 3: Develop artifacts' which included creating architecture diagrams and use cases. What is the immediate next step in the SQUARE methodology?

    Show answer & explanation

    Correct answer: D

    The SQUARE methodology consists of 9 steps. Step 1 is Agree on definitions. Step 2 is Identify security goals. Step 3 is Develop artifacts. Step 4 is Perform risk assessment. After developing the artifacts, the team must assess the risks to identify vulnerabilities and threats before selecting elicitation techniques (Step 5) and actually eliciting the security requirements (Step 6).

  3. Question 3Advanced

    Security Requirements Gathering · Security Requirements Models

    A large healthcare provider is initiating a major overhaul of their patient management system. The organization handles highly sensitive Protected Health Information (PHI) and relies on a mix of legacy on-premises servers and modern cloud infrastructure.

    The Chief Information Security Officer (CISO) mandates a robust, organizational-wide risk assessment before any code is written. The chosen methodology must be self-directed, focus heavily on organizational risks rather than just technological flaws, and specifically build asset-based threat profiles as its primary foundation.

    The security engineering team is evaluating different requirement and risk models. They need a framework that progresses through organizational views, technological views, and finally strategy development.

    Which of the following models is the MOST appropriate for this specific scenario?

    Show answer & explanation

    Correct answer: E

    The OCTAVE model is specifically designed as a self-directed information security risk evaluation methodology. It focuses on organizational risk and strategic practice rather than just technological flaws. Phase 1 builds asset-based threat profiles (organizational view), Phase 2 identifies infrastructure vulnerabilities (technological view), and Phase 3 develops security strategies and plans. SQUARE is focused on eliciting requirements rather than organizational risk profiling. STRIDE is a technical threat modeling tool, not an organizational risk assessment framework.

    flowchart TD A[Phase 1: Build Asset-Based Threat Profiles] --> B[Phase 2: Identify Infrastructure Vulnerabilities] B --> C[Phase 3: Develop Security Strategy and Plans]

  4. Question 4Beginner

    Security Requirements Gathering · Security Requirements Engineering

    During the security requirements gathering phase, a business analyst writes the following requirement: 'The system must prevent a user from attempting more than 5 incorrect login attempts within a 15-minute window.' Which type of artifact does this statement best represent?

    Show answer & explanation

    Correct answer: C

    This is a Security Use Case. It describes the exact behavior the system must exhibit to protect itself against a specific threat (brute force). An Abuse Case would describe the attacker's action (e.g., 'An attacker uses a script to guess passwords rapidly'). A functional use case describes standard user behavior (e.g., 'A user logs in with valid credentials').

  5. Question 5Intermediate

    Security Requirements Gathering · Security Use Cases and Modeling

    In agile development, security requirements are often captured from the perspective of a malicious actor to ensure defenses are built into the sprint. The statement 'As a hacker, I want to intercept session tokens so that I can hijack authenticated user sessions' is an example of a(n) ________.

    Show answer & explanation

    Correct answer: D

    An Abuser Story (also known as an evil user story) is written in the standard agile user story format ('As a [persona], I want [action] so that [outcome]') but from the perspective of a malicious actor. This helps development teams understand the threat context and derive the necessary security stories or acceptance criteria to mitigate the threat.

  6. Question 6Intermediate

    Secure Application Design and Architecture · Threat Modeling

    A security architect is analyzing a proposed ASP.NET Core API. They identify that an attacker could intercept network traffic and alter the product price in the JSON payload before it reaches the server. Which category of the STRIDE model does this specific threat fall under?

    Show answer & explanation

    Correct answer: A

    Tampering involves the malicious modification of data. In this scenario, altering the product price in the JSON payload in transit is a classic Tampering attack. Spoofing is faking an identity. Information Disclosure is unauthorized data reading. Elevation of Privilege is gaining higher access rights.

Ready for the real thing?

The full 312-95 simulator has every exam-style question, timed mode, and instant scoring.

Go to the 312-95 simulator →