
EC-CouncilCertified Application Security Engineer (Java)
Domain 2Objective 2
Secure Application Design and Architecture CASEJAVA Practice Questions (Page 7)
Part of the Security Requirements and Secure Design domain, which makes up ~19% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–5 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 31–35
- 31
A threat modeling team is categorizing threats based on Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. Which threat modeling methodology are they using?
Select an answer first - 32
A Java application stores credit card numbers and must comply with PCI DSS. The design team proposes encrypting all credit card numbers with a single static key stored in the application's configuration file. Which design change is most appropriate?
Select an answer first - 33
Which of the following is a best practice for securely integrating a third-party component?
Select an answer first - 34
A Java-based e-commerce application is being designed. The business requires that customers can browse products without logging in, but must authenticate to place an order. The security team wants to ensure that even if the web tier is compromised, the database credentials cannot be used to directly access the customer database. Which combination of design decisions best satisfies these requirements?
Select an answer first - 35
Which secure architecture pattern ensures that data transmitted between a client and a server is protected from eavesdropping and tampering?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.