
EC-CouncilCertified Application Security Engineer (Java)
Domain 7Objective 2
Secure Auditing and Logging CASEJAVA Practice Questions (Page 8)
Part of the Secure Coding: Error Handling and Logging domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 3–5 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
6concepts
Questions 36–40
- 36
A company's security policy requires that audit logs be protected from unauthorized modification and that any tampering be detectable. Which implementation best meets this requirement?
Select an answer first - 37
A Java application logs user input to a centralized log management system. The security team discovers that an attacker has been injecting forged log entries that appear to come from a legitimate user. The team wants to prevent this while maintaining the ability to log user input for debugging. Which approach is most effective?
Select an answer first - 38
A company's audit logs are stored on a shared network drive. The security team wants to ensure that only authorized personnel can read the logs and that any modification is detected. Which control is most effective?
Select an answer first - 39
What is the primary risk of logging a user's plaintext password in an application log file?
Select an answer first - 40
What is the main purpose of setting up real-time alerting on audit logs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.