Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (Java)

Domain 2Objective 2

Secure Application Design and Architecture CASEJAVA Practice Questions (Page 4)

Part of the Security Requirements and Secure Design domain, which makes up ~19% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–5 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
10concepts

Questions 16–20

  1. 16expert · hard

    A Java application stores personally identifiable information (PII) in a relational database. The design must comply with a regulation that requires data to be encrypted at rest. The team is considering two options: column-level encryption for the PII columns or transparent data encryption (TDE) for the entire database. Which of the following is the most important trade-off to consider?

    Select an answer first
  2. 17expert · hard

    A security architect is leading a threat modeling exercise for a Java application that allows users to upload files. The team uses DREAD for prioritization. They identify a threat where an attacker uploads a malicious file that is later executed on the server. The damage potential is high, reproducibility is high, exploitability is medium, affected users are all users, and discoverability is high. Which of the following actions should the architect take first?

    Select an answer first
  3. 18application · medium

    A team is using DREAD to prioritize threats for a Java application. They have two threats: Threat A has a high damage potential and high likelihood; Threat B has low damage potential and low likelihood. Which threat should be addressed first?

    Select an answer first
  4. 19expert · hard

    A Java application integrates with a third-party identity provider (IdP) using SAML 2.0. The application receives SAML assertions containing user attributes, including role information. The security team is concerned about assertion tampering. Which design control is most effective in mitigating this threat?

    Select an answer first
  5. 20expert · hard

    A Java web application uses role-based access control (RBAC) but needs to support a new requirement where users can share documents with specific individuals. The current RBAC model only supports roles. Which design approach best meets the requirement while maintaining security?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.