
EC-CouncilCertified Application Security Engineer (Java)
Domain 2Objective 1
Security Requirements Gathering CASEJAVA Practice Questions (Page 1)
Part of the Security Requirements and Secure Design domain, which makes up ~19% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–5 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
5concepts
Questions 1–5
- 1
After gathering security requirements for a Java-based payment system, the security lead reviews them with stakeholders. The requirements include strong authentication, encryption of cardholder data, and audit logging. However, the business team notes that the audit logging requirement conflicts with their goal of minimizing storage costs. What is the best way to validate and resolve this conflict?
Select an answer first - 2
A security analyst is validating the security requirements for a Java-based application that will be deployed in a hybrid cloud environment. The requirements include encryption of data in transit, access control, and incident response. During validation, the analyst finds that the incident response requirement does not specify how logs will be aggregated across on-premises and cloud components. What is the best action?
Select an answer first - 3
A security analyst is validating security requirements for a Java-based healthcare system. The requirements include role-based access control (RBAC) and audit logging. During validation, the analyst discovers that the audit logging requirement conflicts with the RBAC requirement because logs would expose sensitive patient data to auditors who lack appropriate roles. What is the best action?
Select an answer first - 4
A security requirement is documented as: 'The application must encrypt all data at rest using AES-256.' What is the PRIMARY benefit of documenting the requirement in this specific, measurable way?
Select an answer first - 5
A multinational company is developing a Java application that handles personal data of users in multiple countries. The security team must identify all applicable security requirements. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.