
EC-CouncilCertified Application Security Engineer (Java)
Domain 2Objective 2
Secure Application Design and Architecture CASEJAVA Practice Questions (Page 2)
Part of the Security Requirements and Secure Design domain, which makes up ~19% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–5 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 6–10
- 6
A Java application is being designed to integrate with a third-party payment API. The architecture must ensure that the API credentials are not exposed to the client-side code and that all communication with the API is encrypted. Which secure architecture pattern should be applied?
Select an answer first - 7
A Java application's logging system currently logs full request headers, including authorization tokens. The security team wants to reduce the risk of token leakage while maintaining auditability. Which approach is most effective?
Select an answer first - 8
An application is designed with separate layers for presentation, business logic, and data access, each with its own security controls. Which secure architecture pattern does this represent?
Select an answer first - 9
A business requirement states that 'the system must allow customers to view their order history.' Which of the following is a well-formed security requirement derived from this business requirement?
Select an answer first - 10
During a security design review of a Java application, the reviewer finds that the application uses a custom encryption algorithm for protecting data at rest. The reviewer also notes that the application does not use any standard security libraries. Which of the following is the most appropriate recommendation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.