Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (Java)

Domain 1Objective 2

Most Common Application-Level Attacks CASEJAVA Practice Questions (Page 8)

Part of the Application Security Foundations domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 2–4 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
5concepts

Questions 36–40

  1. 36application · medium

    An attacker exploits a CSRF vulnerability in a banking application to transfer funds from a logged-in victim's account. The victim's session cookie is automatically sent with the forged request. Which of the following best describes the primary impact of this attack?

    Select an answer first
  2. 37application · medium

    An attacker exploits a stored XSS vulnerability in a public forum. Every time a user views a particular post, the attacker's script steals the user's session cookie and sends it to an external server. Which impact does this attack have on the application's security?

    Select an answer first
  3. 38foundation · easy

    Which attack type occurs when an application fails to properly validate or sanitize user-supplied input before it is included in a database query?

    Select an answer first
  4. 39application · medium

    A development team is reviewing code that constructs SQL queries by concatenating user input. They want to refactor the code to prevent SQL injection. Which approach is the most robust?

    Select an answer first
  5. 40application · medium

    A web application uses a hidden form field to store the user's role (e.g., 'admin' or 'user'). An attacker modifies the hidden field to 'admin' and gains elevated privileges. Which of the following is the most effective mitigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.