
EC-CouncilCertified Application Security Engineer (Java)
Domain 2Objective 1
Security Requirements Gathering CASEJAVA Practice Questions (Page 4)
Part of the Security Requirements and Secure Design domain, which makes up ~19% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–5 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
5concepts
Questions 16–20
- 16
After documenting security requirements for a Java application, the team wants to validate that the requirements are complete and consistent. Which activity is most effective?
Select an answer first - 17
A security lead is documenting security requirements for a Java-based microservices architecture. The requirements include authentication, authorization, and audit logging. The team needs to ensure that each requirement is testable and traceable. However, some requirements are vague, such as 'ensure secure communication.' How should the security lead document this requirement to make it testable?
Select an answer first - 18
A Java-based application is being developed for a financial institution. The security team is gathering requirements from multiple sources: PCI DSS, the company's internal security policy, and a threat model. The threat model identifies a risk that is not covered by PCI DSS or the internal policy. What should the team do?
Select an answer first - 19
A Java-based payment application must meet PCI DSS and also support a business goal of minimizing transaction latency. The security team has gathered requirements including mandatory encryption of cardholder data and a requirement to keep transaction processing under 200 ms. The team must prioritize. What is the most appropriate approach?
Select an answer first - 20
A security team is validating security requirements for a Java application that must comply with PCI DSS. Which validation activity is most important to ensure regulatory alignment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.