Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (Java)

Domain 7Objective 2

Secure Auditing and Logging CASEJAVA Practice Questions (Page 4)

Part of the Secure Coding: Error Handling and Logging domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 3–5 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
6concepts

Questions 16–20

  1. 16expert · hard

    A Java application logs user input to a centralized log management system. The security team wants to prevent log injection while preserving the original input for debugging. Which approach best balances security and usability?

    Select an answer first
  2. 17expert · hard

    A security operations team is overwhelmed by alerts from their SIEM. They want to reduce false positives while ensuring that real security incidents are not missed. The application logs include authentication events, input validation errors, and business logic exceptions. Which strategy is most effective?

    Select an answer first
  3. 18application · medium

    A company is subject to GDPR and must comply with the right to erasure. They store audit logs that contain personal data of users. What is the best approach to handle logs when a user requests deletion of their data?

    Select an answer first
  4. 19application · medium

    A multinational company must comply with GDPR, which requires that personal data not be kept longer than necessary. The company's audit logs contain IP addresses and usernames. The security team is designing a retention policy. Which approach best balances compliance and operational needs?

    Select an answer first
  5. 20application · medium

    A Java application logs user actions to a text file. A user enters the following as a username: "admin\n[ERROR] User logged in". The log entry is written as: "User 'admin\n[ERROR] User logged in' logged in". What is the primary security concern and what should be done?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.