Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (Java)

Domain 4Objective 1

Common Threats on Authentication and Authorization CASEJAVA Practice Questions (Page 9)

Part of the Secure Coding: Authentication and Authorization domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 3–5 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
3concepts

Questions 41–41

  1. 41expert · hard

    A Java application uses a custom authentication filter that checks a token in the Authorization header. The filter does not validate the token's signature or expiration; it only checks that the token exists and is in the database. An attacker who obtains a valid token from a low-privileged user can modify the token's payload to claim admin privileges. What is the most effective fix that also maintains the current stateless authentication design?

    Select an answer first
Finished these 1 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CASEJAVA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.