Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (Java)

Domain 8Objective 2

Secure Deployment and Maintenance CASEJAVA Practice Questions (Page 3)

Part of the Security Testing and Secure Deployment domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 3–5 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
7concepts

Questions 11–15

  1. 11application · medium

    A Java web application is being deployed to a new Linux server in a DMZ. The security team mandates that the application must not expose any unnecessary services, and any runtime errors must not reveal internal stack traces to end users. The deployment team plans to use a systemd service to run the JAR. Which two actions must be part of the deployment plan to satisfy these requirements?

    Select an answer first
  2. 12foundation · easy

    Which action is appropriate when decommissioning a Java application that stored customer data?

    Select an answer first
  3. 13application · medium

    During a routine maintenance window, a Java application is restarted. After the restart, the application fails to connect to the database. The configuration files have not been changed. What is the most likely cause?

    Select an answer first
  4. 14application · medium

    A Java application that stored customer PII is being decommissioned. The database contains both active and archived records. The compliance team requires that all data be unrecoverable after decommissioning, but the operations team needs to retain a copy for a pending legal hold. Which approach satisfies both requirements?

    Select an answer first
  5. 15expert · hard

    A Java application has been running in production for several years. During a security review, it is discovered that the application's runtime environment uses outdated TLS protocols. The application must maintain compatibility with older clients, but the security team requires modern TLS. What is the most appropriate action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.