Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (Java)

Domain 2Objective 2

Secure Application Design and Architecture CASEJAVA Practice Questions (Page 10)

Part of the Security Requirements and Secure Design domain, which makes up ~19% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–5 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
10concepts

Questions 46–50

  1. 46expert · hard

    A Java application is deployed using containers. The security team wants to ensure that the container image does not contain secrets and that runtime configuration is secure. Which approach is most effective?

    Select an answer first
  2. 47foundation · easy

    Which access control model grants permissions based on the roles a user has in an organization?

    Select an answer first
  3. 48application · medium

    During a threat modeling session for a Java web application that handles financial transactions, the team uses STRIDE. They identify that an attacker could tamper with transaction amounts during transmission between the client and server. Which STRIDE threat category does this represent, and what is the most appropriate mitigation to design into the architecture?

    Select an answer first
  4. 49application · medium

    A financial services company is developing a Java application for online fund transfers. The business requirement states: 'Users must be able to transfer funds to any account, but the system must prevent unauthorized transfers.' The security team needs to derive testable security requirements. Which of the following is the most testable and traceable security requirement derived from this business requirement?

    Select an answer first
  5. 50application · medium

    A Java web application requires that users with the 'admin' role can access the admin panel, while regular users cannot. The application uses session-based authentication. Which design approach correctly implements authorization and session management?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.