70-340
- Saturday, November 29, 2008, 22:18
- Exam Details
- 10 views
- 5 comments
Preparation Guide for Exam 70-340
Implementing Security for Applications with Microsoft Visual C# .NET
Updated: September 5, 2008
Exam News
Exam 70-340 became available June 28, 2004.
• This exam is scheduled to retire in March 2009
• This exam is available at 40 percent off retail price until it retires
Audience profile
Candidates for this exam work on an application development team in a software development environment that uses Microsoft Visual Studio .NET 2003. Candidates have at least three years of experience developing n-tier applications and at least one year of experience using Visual Studio .NET 2003, including ASP.NET and ADO.NET. Candidates have experience developing both Web-based and Microsoft Windows-based applications from start to finish.
Credit toward certification
When you pass the Implementing Security for Applications with Microsoft Visual C# .NET exam, you achieve Microsoft Certified Professional status.
• Learn about Microsoft Certified Professional status
You also earn credit toward the following certifications:
• Elective credit toward Microsoft Certified Application Developer (MCAD) for Microsoft .NET certification
• Elective credit toward Microsoft Certified Solution Developer (MCSD) for Microsoft .NET certification
Preparation tools and resources
To help you prepare for this exam, Microsoft Learning recommends that you have hands-on experience with the product and that you use the following training resources. These training resources do not necessarily cover all of the topics listed in the “Skills measured” section.
Classroom training
• Course 2350: Developing and Deploying Secure Microsoft .NET Framework Applications
• Course 2840: Implementing Security for Applications
Microsoft Press and self-paced training products
• MCAD/MCSD Self-Paced Training Kit: Implementing Security for Applications with Microsoft Visual Basic .NET and Microsoft Visual C# .NET (ISBN: 9780735621213)
• Writing Secure Code, Second Edition (ISBN: 9780735617223)
• Improving Web Application Security: Threats and Countermeasures
Microsoft certified practice tests
• MeasureUp: Visit the MeasureUp Web site to take a practice test.
• Self Test Software: Visit the Self Test Software Web site to take a practice test.
Microsoft online resources
• Microsoft Learning Community: Join newsgroups and visit community forums to connect with peers for suggestions on training resources and advice on your certification path and studies.
• TechNet: Designed for IT professionals, this site includes how-to instructions, best practices, downloads, technical resources, newsgroups, and chats.
• MSDN: Designed for developers, the Microsoft Developer Network (MSDN) features code samples, technical articles, downloads, newsgroups, and chats.
Skills measured
This certification exam measures your ability to implement code by using methods to minimize security risks and take advantage of the security functionality built into the .NET Framework. Before taking the exam, you should be proficient in the job skills listed in the following matrix. The matrix shows which Official Microsoft Learning Products may help you reach competency in the skills being tested in the exam.
KEY: = The course provides a general introductory overview of this task. You will need to supplement the course with additional work = The course includes some material to prepare you for this task. You will need to supplement the course with additional work = The course includes material to prepare you for this task
Skills measured by Exam 70-340 Course 2350 Course 2840
Developing Applications by Using Security Best Practices
Develop code under a least privilege account within the development environment.
• Configure the Microsoft .NET development environment and operating system.
• Select the appropriate privileges.
Develop code that runs under a least privilege account at run time.
• Develop code to run under a least privilege account that does not have administrator privileges.
• Use least privilege for access to resources such as the file system, registry entries, and databases.
Analyze security implications of calling unknown code. Third-party components include .NET components, legacy COM components, ActiveX controls, Win32 DLLs, and Web services.
• Write code to verify that the identity of a COM component matches the identity expected.
• Validate that data to and from third-party components conforms to the expected size, format, and type.
• Test for integrity of data after transmission.
• Evaluate unmanaged code.
Write code that addresses failures in a manner that does not compromise security.
• Write code that defaults to a permission set that is more secure than the permission set that existed before the errors or issues occurred.
• Create error messages that do not compromise security.
Develop code that includes security measures in each tier of the solution, also known as defense in depth.
Implement application functionality to apply defaults that minimize security threats.
Write code to prevent canonicalization problems.
• Create canonical references for resources.
• Validate that a reference is canonical.
Validate external input at every boundary level to prevent security problems.
• Write code to test strings by using regular expressions.
• Write code to test the size of data.
• Write code to prevent SQL injection and cross-site scripting.
Donwload Free Certbible, The Most Realistic Practice Questions and Answers,Help You Pass any Exams
Developing .NET Applications That Include Security Enhancements
Implement security by using application domains.
Implement authentication.
• Implement a custom authentication mechanism in a Windows Forms application.
• Implement an appropriate Web application or Web service authentication mechanism to accommodate specific application security requirements.
• Implement functionality by consuming authenticated user information such as the IPrincipal, Membership, and Identity components of the .NET base class library.
Write authorization code.
• Programmatically control access to functionality and data by using user information such as user identity, group membership, and other custom user information.
• Control access to Web applications by using URL authorization.
• Programmatically control access to functionality and data by using identities or criteria that are independent of user identity.
Sign data by using certificates.
Implement data protection.
• Use .NET cryptographic techniques.
• Encrypt and decrypt data by using symmetric and asymmetric cryptographic functions.
• Compute hashes by using cryptographic functions.
• Write code to create cryptographically random numbers for cryptographic functions.
• Protect data in files and folders by creating, modifying, and deleting discretionary access control list (DACL) or security access control list (SACL) entries.
• Encrypt and decrypt data by using the Data Protection API (DPAPI).
Implement security for an application or shared library by using .NET code access security.
• Demand a code access permission such as FileIOPermission.
• Group code access permissions into a permission set.
• Override code access security checks.
• Protect a resource in a library.
• Specify the permission requests of an application.
• Customize code access security.
Access remote functionality in a manner that minimizes security risks.
• Use Web Services Enhancements (WSE) for Microsoft .NET, such as WS-Security and WS-Interoperability.
• Configure .NET Remote for security.
Configuring Application Security by Using the Microsoft .NET Framework and Operating System Tools
Work with .NET security policies. Tools include the .NET Framework Configuration tool and the Code Access Security Policy tool.
Analyze the code access permissions of an assembly by using the Permissions View tool.
Configure security by using IIS and ASP.NET.
• Understand the security implications of impersonation.
• Configure ASP.NET impersonation.
• Configure Web folder permissions.
• Set appropriate permissions on Web application files.
• Configure a Web page or Web service to use SSL/TLS.
Stabilizing and Releasing Applications in a Manner That Minimizes Security Risks
Perform unit testing on applications and components to identify security vulnerabilities.
Release applications in a manner that minimizes security risks.
• Evaluate when to sign an assembly.
• Implement delayed signing.
• Create a strong named assembly.
• Configure security settings by using the .NET Framework Configuration tool and the Code Access Security Policy tool at deployment.
The microsoft 70-340 certificates give you possibility to work in any country of the world because they are acknowledged in all countries equally. This microsoft 70-340 torrent certificate helps
not only to improve your knowledge and skills, but it also helps your career, gives a possibility for qualified usage of microsoft 70-340 exam products under different conditions. The
majority of companies in the sphere of information technologies require the presence of microsoft 70-340 exams for the work in the company, and that makes obtaining this microsoft 70-340
certificate necessary. Many IT specialists were not able to obtain the real microsoft 70-340 certificate from the first attempt, which was the result of poor preparation for the
examination, using preparatory microsoft 70-340 study guide of poor quality.
The leader among the providers of microsoft 70-340 preparatory materials is products such as microsoft 70-340 vce pdf Braindumps, microsoft 70-340 Tutorial, microsoft 70-340 Exam Questions with Answers, microsoft 70-340
Trainings, microsoft 70-340 Test Online Simulations Course and free PDF. It obtained its leadership and trust of the users from the very beginning of its work on the microsoft 70-340 training
materials market. All the microsoft 70-340 value pack aids have been created by people who are personally familiar with actualtests microsoft 70-340 Preparation Labs and who know all the
difficulties and popular mistakes made by those who take a microsoft 70-340 . The entire material is logically composed in such a way that everything becomes easy to understand for
anyone. full download Many microsoft 70-340 guides include audio and video material. It is really easy to acquire microsoft 70-340 exams because of great variety of methods of payment.
pass4sure testking microsoft 70-340 transcender rapidshare 4shared links
| certification braindumps |
|
Type |
Exam Bible | New Questions & Answers |
Latest Updated |
Download link |
![]() |
All Certbible 's Exam Pack |
597 |
1 days ago | Available |
Realted Post
Top Posts for Today
- Packet Tracer 5.0 Full Version (158 views)
- Cisco Packet Tracer 5.0 Beta4 (95 views)
- Packet Tracer 5.1 for Windows with Cisco Official tutorials (92 views)
- How to Open VCE Files (86 views)
- Free Certification Bible Dumps and IT eBooks (80 views)
- All crack Pass4sure Exams (78 views)
- SAP Ebooks Megapost - 2 - AF (58 views)
- microsoft press ebooks (49 views)
- New Pass4sure Cisco CCNA 640-802 V3.20 Dumps (47 views)
- Draft of New PMBOK - PMBOK 4th edition is now available (45 views)
Visited 122 times, 1 so far today
About the Author
5 Comments on “70-340”
Trackbacks
- testking microsoft MCAD 70-340 | Donwload Free Latest TK Certification Exams Rapidshare Vce Training Braindumps
- Testking Microsoft 70-340 | Download Free Latest Testking Certification Exams Training vce PDF Materials Braindumps
- Actualtests microsoft 70-340 | Download Free Latest Microsoft Certification Training Exams rapidshare vce PDF
- Pass4sure microsoft 70-340 | Download Free Latest Pass4sure Certification Exams Training Materials Rapidshre Braindumps
- Microsoft 70-340 Study Materials with Actual 70-340 Exam Answers | Download Latest Testinsdie 70-340 PDF Test Braindumps Sadikhov Links
Write a Comment
Gravatars are small images that can show your personality. You can get your gravatar for free today!
















