Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (Java)

Domain 2Objective 1

Security Requirements Gathering CASEJAVA Practice Questions (Page 10)

Part of the Security Requirements and Secure Design domain, which makes up ~19% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–5 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
5concepts

Questions 46–50

  1. 46application · medium

    A Java-based healthcare portal stores patient records and is subject to HIPAA. During requirements gathering, the security lead interviews the compliance officer, reviews the organization's data-handling policy, and runs a threat model. Which requirement should be prioritized as the primary driver for the access-control design?

    Select an answer first
  2. 47expert · hard

    A security architect is prioritizing security requirements for a Java-based application that will be used by multiple tenants. The threat model identifies a high-severity risk of cross-tenant data leakage and a medium-severity risk of denial-of-service. The business team wants to maximize feature velocity. Which requirement should be prioritized?

    Select an answer first
  3. 48expert · hard

    A security team is validating security requirements for a Java-based application that is subject to multiple regulations. The requirements have been documented, but the team is unsure whether they are complete. What is the most effective validation technique?

    Select an answer first
  4. 49foundation · easy

    A project team wants to elicit security requirements by bringing together stakeholders from development, operations, and legal to discuss and reach consensus on security controls. Which elicitation technique is being used?

    Select an answer first
  5. 50application · medium

    A mobile banking app team is eliciting security requirements. The stakeholders are geographically distributed and have limited availability. The security lead needs to gather input from all of them efficiently. Which elicitation technique is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CASEJAVA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.