
EC-CouncilCertified Application Security Engineer (Java)
Domain 1Objective 2
Most Common Application-Level Attacks CASEJAVA Practice Questions (Page 2)
Part of the Application Security Foundations domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 2–4 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
5concepts
Questions 6–10
- 6
A Java web application accepts a product ID from a URL parameter and directly concatenates it into a SQL query. An attacker submits `productId=1 OR 1=1` and retrieves all product records. Which vulnerability class does this attack map to, and what is the most effective mitigation?
Select an answer first - 7
Which impact is most directly associated with a successful SQL injection attack?
Select an answer first - 8
Which technique is commonly used to carry out an insecure deserialization attack?
Select an answer first - 9
A Java application deserializes objects from an HTTP request without any validation. An attacker crafts a malicious serialized object that, when deserialized, executes arbitrary commands on the server. Which OWASP Top 10 vulnerability class does this attack belong to, and what is a key mitigation?
Select an answer first - 10
A Java web application has a search feature that reflects user input in the page without encoding. An attacker crafts a URL that, when clicked by an admin, executes JavaScript in the admin's browser session. Which attack is being executed, and which primary defense would block it?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.