
EC-CouncilCertified Application Security Engineer (Java)
Domain 1Objective 2
Most Common Application-Level Attacks CASEJAVA Practice Questions (Page 1)
Part of the Application Security Foundations domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 2–4 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
5concepts
Questions 1–5
- 1
A security review finds that an application's error pages expose stack traces and database connection strings to end users. Which OWASP Top 10 category does this fall under, and what is the primary risk?
Select an answer first - 2
Which OWASP Top 10 vulnerability class is the root cause of SQL injection attacks?
Select an answer first - 3
What is the primary impact of a stored cross-site scripting (XSS) attack on an application's users?
Select an answer first - 4
An attacker exploits a path traversal vulnerability to access `/etc/passwd` on the server. The application fails to validate user-supplied file paths. Which of the following best describes the impact on the CIA triad?
Select an answer first - 5
During a penetration test, a tester discovers that the application's login form allows an attacker to submit a crafted username that changes the SQL query to bypass authentication. Which OWASP Top 10 category best describes this vulnerability, and what is the primary impact?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.