Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (Java)

Domain 8Objective 2

Secure Deployment and Maintenance CASEJAVA Practice Questions (Page 1)

Part of the Security Testing and Secure Deployment domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 3–5 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
7concepts

Questions 1–5

  1. 1expert · hard

    A Java application's configuration management system uses a central server to push configuration changes. The security team wants to ensure that only authorized administrators can make changes, but the operations team needs to be able to quickly revert changes if they cause issues. Which approach best meets both requirements?

    Select an answer first
  2. 2foundation · easy

    Which logging practice is most effective for detecting security incidents in a Java application?

    Select an answer first
  3. 3application · medium

    A financial services company runs a Java application on Tomcat with a MySQL backend. A recent audit found that the application connects to the database using the 'root' account with a password stored in a properties file on the classpath. The security team requires a quick remediation that reduces the blast radius of a credential leak without requiring a full application rewrite. Which approach best addresses the finding?

    Select an answer first
  4. 4application · medium

    A DevOps team is automating the deployment of a Java microservice to a Kubernetes cluster. The security policy requires that container images be scanned for vulnerabilities before deployment. Which control should be integrated into the CI/CD pipeline?

    Select an answer first
  5. 5application · medium

    A security analyst is configuring logging for a Java application that handles payment transactions. The compliance team requires that any security-relevant event, such as a failed login or a payment authorization failure, must be recorded with enough detail to support a forensic investigation. The application uses SLF4J with Logback. Which logging configuration best meets this requirement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.