Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (Java)

Domain 2Objective 1

Security Requirements Gathering CASEJAVA Practice Questions (Page 2)

Part of the Security Requirements and Secure Design domain, which makes up ~19% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–5 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
5concepts

Questions 6–10

  1. 6application · medium

    A financial services firm is gathering security requirements for a new Java-based transaction system. Stakeholders include the compliance team, developers, and operations staff, who have conflicting priorities. The security lead wants to elicit requirements efficiently while ensuring all perspectives are captured. Which approach is most effective?

    Select an answer first
  2. 7application · medium

    A startup is building a social media platform and has gathered security requirements from various sources. The threat model identifies a high-risk vulnerability in user authentication, while a business policy requires minimal user friction. The team must prioritize requirements. Which requirement should be addressed first?

    Select an answer first
  3. 8expert · hard

    A security analyst is validating the security requirements for a Java-based application that processes credit card data. The requirements include encryption of cardholder data, access control, and audit logging. During validation, the analyst finds that the audit logging requirement does not specify retention duration, which conflicts with the company's data minimization policy. What is the best course of action?

    Select an answer first
  4. 9application · medium

    A security analyst is eliciting security requirements for a Java-based mobile banking app. The stakeholders include security experts, UX designers, and product managers. The analyst wants to identify conflicting requirements early. Which technique is best?

    Select an answer first
  5. 10expert · hard

    A security analyst is documenting security requirements for a Java-based system. The requirements were gathered from multiple stakeholders and include conflicting statements. What is the best way to document these requirements to support validation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.