Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (Java)

Domain 1Objective 2

Most Common Application-Level Attacks CASEJAVA Practice Questions (Page 4)

Part of the Application Security Foundations domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 2–4 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
5concepts

Questions 16–20

  1. 16application · medium

    An attacker exploits a path traversal vulnerability in a file download feature. By sending '../' sequences, they retrieve the application's configuration file containing database credentials. Which impact does this have on the application's security?

    Select an answer first
  2. 17foundation · easy

    According to the OWASP Top 10, which vulnerability class does a cross-site request forgery (CSRF) attack fall under?

    Select an answer first
  3. 18foundation · easy

    Which of the following is a general mitigation for cross-site scripting (XSS)?

    Select an answer first
  4. 19application · medium

    A Java web application allows users to upload profile pictures. An attacker uploads a file containing malicious JavaScript and accesses it via a direct URL, causing the script to execute in other users' browsers. Which of the following is the most effective mitigation?

    Select an answer first
  5. 20application · medium

    An attacker sends a large number of requests containing deeply nested JSON payloads to a REST API. The API server spends excessive CPU time parsing these payloads, causing legitimate requests to time out. Which attack mechanism is being used, and what is the primary impact?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.